Loading HuntDB...

GHSA-xjr3-fwp9-9g96

GitHub Security Advisory

Moodle Cross-Site Request Forgery (CSRF)

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

Affected Packages

Packagist moodle/moodle
Affected versions: 3.11 (fixed in 3.11.9)
Packagist moodle/moodle
Affected versions: 4.0 (fixed in 4.0.3)

Related CVEs

Key Information

GHSA ID
GHSA-xjr3-fwp9-9g96
Published
October 6, 2022 6:52 PM
Last Modified
April 23, 2024 11:43 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
moodle/moodle
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.