← back
CVE-2024-34007highCWE-352

moodle: logout CSRF in admin/tool/mfa/auth.php

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Moodle