Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A flaw was found in Moodle. The XML grade import functionality, which allows setting or overwriting of student grades, did not include the token required to prevent a cross-site request forgery (CSRF) risk, allowing an attacker to overwrite grades on behalf of a logged-in victim who visits a malicious page.