The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:moodle:moodle:4.1.0:-:*:*:*:*:*:*",
"cpe:2.3:a:moodle:moodle:4.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
]
}