CVE-2024-43434

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

01 May 2025, 16:03

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2304262 - () https://bugzilla.redhat.com/show_bug.cgi?id=2304262 - Permissions Required
References () https://moodle.org/mod/forum/discuss.php?d=461203 - () https://moodle.org/mod/forum/discuss.php?d=461203 - Vendor Advisory
First Time Moodle moodle
Moodle
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

08 Nov 2024, 19:01

Type Values Removed Values Added
Summary
  • (es) La función de envío masivo de mensajes en el informe de no respuestas del módulo de comentarios de Moodle tenía una verificación de token CSRF incorrecta, lo que generaba una vulnerabilidad CSRF.

07 Nov 2024, 16:35

Type Values Removed Values Added
CWE CWE-22

07 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 14:15

Updated : 2025-05-01 16:03


NVD link : CVE-2024-43434

Mitre link : CVE-2024-43434

CVE.ORG link : CVE-2024-43434


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')