Description
Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.
Remediation
References
Related Vulnerabilities
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-13376)
WordPress Plugin Twitter Button by BestWebSoft Cross-Site Request Forgery (2.14)
Joomla! Core Security Bypass (1.6.0 - 3.9.24)
WordPress Plugin LearnPress-WordPress LMS Security Bypass (3.2.6.6)
Oracle Application Server Other Vulnerability (CVE-2005-3204)