CVE-2024-34007: Moodle
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
Affected products
- Moodle Moodle: from 4.3.0, before 4.3.4 (fixed in 4.3.4)
Published 2024-05-31. Last modified 2026-06-17.