The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
{ "github_reviewed_at": "2024-11-07T18:27:26Z", "severity": "HIGH", "nvd_published_at": "2024-11-07T14:15:16Z", "github_reviewed": true, "cwe_ids": [ "CWE-22", "CWE-352" ] }