Description
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
Remediation
References
Related Vulnerabilities
Coppermine Improper Authentication Vulnerability (CVE-2005-3979)
Liferay Portal Missing Authorization Vulnerability (CVE-2022-39975)
WordPress Plugin Doneren met Mollie Information Disclosure (2.8.4)
WordPress Plugin Attachment Manager Arbitrary File Upload (2.1.1)
WordPress Plugin Z-Vote 'zvote' Parameter SQL Injection (1.1)