The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
{ "cpes": [ "cpe:2.3:a:moodle:moodle:4.1.0:-:*:*:*:*:*:*", "cpe:2.3:a:moodle:moodle:4.1.1:*:*:*:*:*:*:*", "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*" ], "severity": "High" }