The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
- | 4.1.12 |
moodle / moodle
|
4.2.0 | 4.2.9 |
moodle / moodle
|
4.3.0 | 4.3.6 |
moodle / moodle
|
4.4.0 | 4.4.2 |