Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in Moodle. The XML grade import functionality, which allows setting or overwriting of student grades, did not include the token required to prevent a cross-site request forgery (CSRF) risk, allowing an attacker to overwrite grades on behalf of a logged-in victim who visits a malicious page.