Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
{ "severity": "High", "cpes": [ "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*" ] }