PT-2024-25636 · Moodle+2 · Moodle+2

Paul Holden

·

Published

2024-05-31

·

Updated

2024-07-19

·

CVE-2024-34008

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description The issue concerns a CSRF risk in the admin management of analytics models due to the lack of a necessary token. This could allow unauthorized actions on behalf of users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

CSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2024-8851
ALT-PU-2024-9067
BIT-MOODLE-2024-34008
CVE-2024-34008
GHSA-68X5-4JG5-GJGG

Affected Products

Alt Linux
Moodle
Red Os