Vulnerability Name: | CVE-2009-0499 (CCN-48500) |
Assigned: | 2009-02-04 |
Published: | 2009-02-04 |
Updated: | 2020-12-01 |
Summary: | Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): Partial | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-352
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2009-0499
Source: CCN Type: moodle CVS Repository Diff of /moodle/mod/forum/post.php
Source: CONFIRM Type: UNKNOWN http://cvs.moodle.org/moodle/mod/forum/post.php?r1=1.154.2.14&r2=1.154.2.15
Source: SUSE Type: UNKNOWN SUSE-SR:2009:007
Source: CCN Type: MSA-09-0008 CSRF vulnerability in forum code
Source: CONFIRM Type: UNKNOWN http://moodle.org/security/
Source: CCN Type: SA33775 Moodle Multiple Vulnerabilities
Source: SECUNIA Type: UNKNOWN 34418
Source: CCN Type: Moodle Tracker Web site MDL-17799
Source: MLIST Type: UNKNOWN [oss-security] 20090204 CVS request - Moodle
Source: CCN Type: OSVDB ID: 54085 Moodle Forum post.php Unauthorized Post Deletion CSRF
Source: CCN Type: BID-33615 Moodle Forum Unspecified Cross-Site Request Forgery Vulnerability
Source: CCN Type: USN-791-1 Moodle vulnerabilities
Source: XF Type: UNKNOWN moodle-post-csrf(48500)
Source: SUSE Type: SUSE-SR:2009:007 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration 1: cpe:/a:moodle:moodle:1.7.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:moodle:moodle:1.7.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.6:*:*:*:*:*:*:*AND cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |