CVE-2021-43559

HIGH

Moodle < 3.8.8, 3.9-3.9.10, 3.10-3.10.7, 3.11-3.11.3 - Cross-Site Request Forgery via Badge Deletion

Title source: llm
STIX 2.1

Description

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2021517
Patch, Vendor Advisory x_refsource_misc
https://moodle.org/mod/forum/discuss.php?d=429099

Scores

CVSS v3 8.8
EPSS 0.0011
EPSS Percentile 28.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (4)
fedoraproject/extra_packages_for_enterprise_linux 7.0
fedoraproject/fedora 35
moodle/moodle < 3.8.8
moodle/moodle 3.11 - 3.11.4Packagist
Published Nov 22, 2021
Tracked Since Feb 18, 2026