Описание
Moodle cross-site request forgery (CSRF) vulnerability
Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-0126
- https://github.com/moodle/moodle/commit/41a19bffeef0ee6b0560a5ff808fd4bd35075fa1
- https://github.com/moodle/moodle/commit/caf766507771e07c1752ece1f37a32b2b4f6d8b9
- https://github.com/moodle/moodle/commit/ea8647b39ec9cf1d73e04b05559bd12d97aa5229
- https://github.com/moodle/moodle/commit/eee61675f042a9ec89f8f6d219b4ded010198fe4
- https://moodle.org/mod/forum/discuss.php?d=256423
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43146
- http://openwall.com/lists/oss-security/2014/03/17/1
Пакеты
moodle/moodle
< 2.4.9
2.4.9
moodle/moodle
>= 2.5.0, < 2.5.5
2.5.5
moodle/moodle
>= 2.6.0, < 2.6.2
2.6.2
Связанные уязвимости
Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.
Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.
Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise ...