Vulnerability Bulletins

MSA-24-0005: CSRF risk in Language import utility


System information

   
Affected software PHP

Description

por Michael Hawkins. The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.Severity/Risk:MinorVersions affected:4.3 to 4.3.2, 4.2 to 4.2.5, 4.1 to 4.1.8 and earlier unsupported versionsVersions fixed:4.3.3, 4.2.6 and 4.1.9Reported by:Panagiotis PetasisCVE identifier:CVE-2024-25982Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-54749Tracker issue:MDL-54749 CSRF risk in Language import

More info:

https://moodle.org/mod/forum/discuss.php?d=455638&parent=1830382

Standar resources

Property Value
CVE CVE-2024-25982.

Version history

Version Comments Date
Ministerio de Defensa
CNI
CCN
CCN-CERT