Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Msa-24-0005: csrf risk in language import utility
Vulnerability Description
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
moodle 安全漏洞
Vulnerability Description
Moodle是一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 moodle存在安全漏洞,该漏洞源于更新所有已安装语言包的链接不包含防止跨站请求伪造风险所需的令牌。
CVSS Information
N/A
Vulnerability Type
N/A