CVE-2025-3638
Moodle: csrf risk in brickfield tool's analysis request action
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.
| CWE | CWE-352 |
| Published | Apr 25, 2025 |
| Last Updated | Apr 28, 2025 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new high vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
References
Credits
Red Hat would like to thank Vincent Schneider for reporting this issue.