GHSA-8hxm-42v5-66hm
Dashboard / Vulnerabilities / GHSA-8hxm-42v5-66hm
Summary: Moodle vulnerable to Cross-Site Request Forgery
Details: Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.
References: https://nvd.nist.gov/vuln/detail/CVE-2011-4298, https://bugzilla.redhat.com/show_bug.cgi?id=747444, https://git.moodle.org, http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=48346fb11f8ced06a05c0618b02a3a925b34ec59, http://git.moodle.org/gw?p=moodle.git;a=commit;h=48346fb11f8ced06a05c0618b02a3a925b34ec59, http://moodle.org/mod/forum/discuss.php?d=188309
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: ECOSYSTEM
Events:
