CVE-2018-16854
Description
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.
CWE
- CWE-352 — CWE-352
Affected
- [UNKNOWN] / moodle — v=3.6 [affected]; v=3.5.3 [affected]; v=3.4.6 [affected]; v=3.3.9 [affected]; v=3.1.15 [affected]
CVSS
- 3.0 score=6.5 severity=MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16854 x_refsource_CONFIRM
- http://www.securitytracker.com/id/1042154 vdb-entry, x_refsource_SECTRACK
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-63183 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/106017 vdb-entry, x_refsource_BID
- https://moodle.org/mod/forum/discuss.php?d=378731 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2018/16xxx/CVE-2018-16854.json