CVE-2011-4281

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:09

Type Values Removed Values Added
References
  • {'url': 'http://git.moodle.org/gw?p=moodle.git;a=commit;h=9cedb80c5d6318aa17cd66912d37e6ef3dca9455', 'name': 'http://git.moodle.org/gw?p=moodle.git;a=commit;h=9cedb80c5d6318aa17cd66912d37e6ef3dca9455', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • () http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=9cedb80c5d6318aa17cd66912d37e6ef3dca9455 -

Information

Published : 2012-07-16 10:28

Updated : 2023-11-07 02:09


NVD link : CVE-2011-4281

Mitre link : CVE-2011-4281


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-352

Cross-Site Request Forgery (CSRF)