The XML grade import functionality (which allows setting or overwriting of student grades) did not include the necessary token to prevent a CSRF risk.
| Severity/Risk: | Serious |
| Versions affected: | 5.2 to 5.2.1, 5.1 to 5.1.5, 5.0 to 5.0.8, 4.5 to 4.5.12 and earlier unsupported versions |
| Versions fixed: | 5.2.2, 5.1.6, 5.0.9 and 4.5.13 |
| Reported by: | Vincent Schneider |
| CVE identifier: | Pending (details will be updated once available) |
| Changes (main): | http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84545 |
| Tracker issue: | MDL-84545 CSRF risk in XML grade imports |