CVE-2022-2986
Description
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
CWE
- (none)
Affected
- n/a / moodle — v=moodle 4.0.3 and moodle 3.11.9 [affected]
CVSS
- (none)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2121360
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75326
Source
cvelistV5-main/cves/2022/2xxx/CVE-2022-2986.json