A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2025-3638 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2359732 | third party advisory issue tracking |
https://moodle.org/mod/forum/discuss.php?d=467600 | vendor advisory |