Boletines de Vulnerabilidades

MSA-24-0005: CSRF risk in Language import utility


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.Severity/Risk:MinorVersions affected:4.3 to 4.3.2, 4.2 to 4.2.5, 4.1 to 4.1.8 and earlier unsupported versionsVersions fixed:4.3.3, 4.2.6 and 4.1.9Reported by:Panagiotis PetasisCVE identifier:CVE-2024-25982Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-54749Tracker issue:MDL-54749 CSRF risk in Language import

More info:

https://moodle.org/mod/forum/discuss.php?d=455638&parent=1830382

Identificadores estándar

Propiedad Valor
CVE CVE-2024-25982.

Histórico de versiones

Versión Comentario Data
Ministerio de Defensa
CNI
CCN
CCN-CERT