Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
- >= 4.5, <= 4.5.3
- >= 4.4, <= 4.4.7
- >= 4.3, <= 4.3.11
- >= 4.1, <= 4.1.17
A cross-site request forgery (CSRF) vulnerability in Moodle's User Tours Manager allows users to duplicate existing tours without logging in. This issue arises from a lack of CSRF protection in the tour duplication feature.
Exploitation of this vulnerability allows for unauthorized duplication of user tours in Moodle.
Users can upgrade to Moodle versions 4.5.4, 4.4.8, 4.3.12, or 4.1.18 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.