A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victims behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.
The product does not properly verify that the source of data or communication is valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Moodle | Moodle | * | 4.5.13 (excluding) |
| Moodle | Moodle | 5.0.0 (including) | 5.0.9 (excluding) |
| Moodle | Moodle | 5.1.0 (including) | 5.1.6 (excluding) |
| Moodle | Moodle | 5.2.0 (including) | 5.2.2 (excluding) |