CVE-2024-43434

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
Configurations

No configuration.

History

08 Nov 2024, 19:01

Type Values Removed Values Added
Summary
  • (es) La función de envío masivo de mensajes en el informe de no respuestas del módulo de comentarios de Moodle tenía una verificación de token CSRF incorrecta, lo que generaba una vulnerabilidad CSRF.

07 Nov 2024, 16:35

Type Values Removed Values Added
CWE CWE-22

07 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 14:15

Updated : 2024-11-08 19:01


NVD link : CVE-2024-43434

Mitre link : CVE-2024-43434

CVE.ORG link : CVE-2024-43434


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')