CVE-2022-45149

MEDIUM5.4EPSS 0.30%

Cross-Site Request Forgery in Moodle

發布日:2022/11/23修改日:2024/2/18
也稱為:GHSA-8v23-w4w5-w83cBIT-moodle-2022-45149

描述

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

參考連結(10)