CVE-2018-16854

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
26/11/2018
Last modified:
09/10/2019

Description

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.0.10 (including)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.15 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.3.0 (including) 3.3.9 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.6 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.3 (excluding)