PT-2022-9027 · Moodle · Moodle-Block Sitenews

Published

2022-12-27

·

Updated

2024-05-17

·

CVE-2020-36633

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions moodle-block sitenews version 1.0
Description A vulnerability was found in the get content function of the block sitenews.php file, leading to cross-site request forgery. The attack can be initiated remotely.
Recommendations For moodle-block sitenews version 1.0, upgrade to version 1.1 to address this issue. As a temporary workaround, consider restricting access to the get content function of the block sitenews.php file until the upgrade is applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-36633

Affected Products

Moodle-Block Sitenews