Description
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0738)
WordPress Plugin MPL-Publisher-Create your Ebook & Audiobook Cross-Site Scripting (1.29.1)
Oracle JRE CVE-2013-0449 Vulnerability (CVE-2013-0449)
WordPress Plugin SyntaxHighlighter Evolved Cross-Site Scripting (3.1.5)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-2348)