The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8g5h-gjwq-w5ch | Moodle Logout CSRF in admin/tool/mfa/auth.php |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://moodle.org/mod/forum/discuss.php?d=458396 |
|
History
Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-11-21T19:15:00.462Z
Reserved: 2024-04-29T13:02:30.267Z
Link: CVE-2024-34007
Updated: 2024-08-02T02:42:59.880Z
Status : Analyzed
Published: 2024-05-31T21:15:09.647
Modified: 2025-05-30T16:48:34.143
Link: CVE-2024-34007
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA