GHSA-gq9f-8rj4-w7jc
GitHub Security Advisory
Moodle CSRF risk in admin preset tool management of presets
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
Affected Packages
Packagist
moodle/moodle
Affected versions:
4.3.0
(fixed in 4.3.4)
Packagist
moodle/moodle
Affected versions:
4.2.0
(fixed in 4.2.7)
Packagist
moodle/moodle
Affected versions:
0
(fixed in 4.1.10)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 13, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.