Bugzilla – Bug 1116913
VUL-0: CVE-2018-16854: moodle: Login CSRF vulnerability in login form
Last modified: 2018-11-21 17:01:27 UTC
rh#1652020 A flaw was found in moodle before versions 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15. The login form is not protected by a token to prevent login cross-site request forgery. References: https://moodle.org/mod/forum/discuss.php?d=378731 Upstream Patch: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-63183 References: https://bugzilla.redhat.com/show_bug.cgi?id=1652020 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-16854 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16854
* Updated moodle3_1, moodle3_4 and moodle3_5 package in Education. * Updated internal moodle instance as well => closing here, thanks for notifying!