A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/109175 | vdb entry third party advisory broken link |
https://moodle.org/mod/forum/discuss.php?d=388567#p1566329 | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10186 | issue tracking third party advisory |