CVE-2014-7838 Information
Feb 14, 2021
cve
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11 2.5.x before 2.5.9 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php (2) mod/forum/forum.js (3) mod/forum/index.php or (4) mod/forum/lib.php.
Reference
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-48019 http://openwall.com/lists/oss-security/2014/11/17/11 http://www.securitytracker.com/id/1031215 https://moodle.org/mod/forum/discuss.php?d=275164
Share on: