Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.
Remediation
References
Related Vulnerabilities
WordPress Plugin The Plus Addons for Elementor Security Bypass (4.1.10)
ReviveAdserver 7PK - Security Features Vulnerability (CVE-2016-9470)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-1927)
WordPress Plugin Registrations for the Events Calendar-Event Registration SQL Injection (2.7.5)