CVE-2024-43434
07.11.2024, 14:15
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 4.1.12 |
moodle | moodle | 4.2.9 < 𝑥 < 4.2.9 |
moodle | moodle | 4.3.6 < 𝑥 < 4.3.6 |
moodle | moodle | 4.4.2 < 𝑥 < 4.4.2 |
moodle | moodle | 𝑥 < 4.1.12 |
moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.9 |
moodle | moodle | 4.3.0 ≤ 𝑥 < 4.3.6 |
moodle | moodle | 4.4.0 ≤ 𝑥 < 4.4.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases