The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-22",
"CWE-352"
],
"nvd_published_at": "2024-11-07T14:15:16Z",
"github_reviewed_at": "2024-11-07T18:27:26Z"
}