Total vulnerabilities in the database
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
Software | From | Fixed in |
---|---|---|
![]() |
4.3.0 | 4.3.4 |
moodle / moodle | 4.3.0 | 4.3.4 |