GHSA-7cvw-wrj9-q5fp
Dashboard / Vulnerabilities / GHSA-7cvw-wrj9-q5fp
Summary: Moodle vulnerable to Cross-Site Request Forgery
Details: Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.
References: https://nvd.nist.gov/vuln/detail/CVE-2011-4133, https://github.com/moodle/moodle, http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=8f031d5431c1204197b1482fd6c63bc87a19a476, http://git.moodle.org/gw?p=moodle.git;a=commit;h=8f031d5431c1204197b1482fd6c63bc87a19a476, http://moodle.org/mod/forum/discuss.php?d=170002, http://openwall.com/lists/oss-security/2011/11/14/1
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: ECOSYSTEM
Events:
