CVE-2019-10186: Moodle
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
Affected products
- Moodle Moodle: before 3.5.7 (fixed in 3.5.7); from 3.6.0, before 3.6.5 (fixed in 3.6.5); from 3.7.0, before 3.7.1 (fixed in 3.7.1)
Published 2019-07-31. Last modified 2026-06-17.