A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "4.3.12"
},
{
"introduced": "4.4.0"
},
{
"fixed": "4.4.8"
},
{
"introduced": "4.5.0"
},
{
"fixed": "4.5.4"
}
]
}