A flaw was found in Moodle. The actions to enable and disable group messaging did not include the necessary token to prevent a Cross-Site Request Forgery (CSRF) risk. A remote attacker could exploit this by tricking an authenticated user into performing unintended actions, potentially leading to unauthorized changes in group messaging settings.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.cve.org/CVERecord?id=CVE-2026-58341 |
|
History
Tue, 28 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| Vendors & Products |
Moodle
Moodle moodle |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Moodle. The actions to enable and disable group messaging did not include the necessary token to prevent a Cross-Site Request Forgery (CSRF) risk. A remote attacker could exploit this by tricking an authenticated user into performing unintended actions, potentially leading to unauthorized changes in group messaging settings. | |
| Title | moodle: CSRF risk in group messaging state toggle | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T18:30:04Z