Описание
Moodle vulnerable to Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2011-4133
- http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=8f031d5431c1204197b1482fd6c63bc87a19a476
- http://git.moodle.org/gw?p=moodle.git;a=commit;h=8f031d5431c1204197b1482fd6c63bc87a19a476
- http://moodle.org/mod/forum/discuss.php?d=170002
- http://openwall.com/lists/oss-security/2011/11/14/1
Пакеты
moodle/moodle
>= 1.9.0, < 1.9.11
1.9.11
Связанные уязвимости
Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.
Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.
Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before ...