Vulnerability Name: | CVE-2010-2231 (CCN-59546) |
Assigned: | 2010-06-17 |
Published: | 2010-06-17 |
Updated: | 2020-12-01 |
Summary: | Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid parameter.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-352
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2010-2231
Source: CONFIRM Type: Patch http://cvs.moodle.org/moodle/mod/quiz/report/overview/report.php?r1=1.98.2.50&r2=1.98.2.51
Source: CONFIRM Type: UNKNOWN http://docs.moodle.org/en/Moodle_1.8.13_release_notes
Source: CONFIRM Type: UNKNOWN http://docs.moodle.org/en/Moodle_1.9.9_release_notes
Source: FEDORA Type: UNKNOWN FEDORA-2010-10286
Source: FEDORA Type: UNKNOWN FEDORA-2010-10291
Source: FEDORA Type: UNKNOWN FEDORA-2010-10321
Source: SUSE Type: UNKNOWN SUSE-SR:2010:014
Source: CCN Type: Moodle Web site Moodle.org: open-source community-based tools for learning
Source: CCN Type: MSA-10-0013 Potential Cross Site Request Forgery vulnerability in Quiz reports
Source: CONFIRM Type: UNKNOWN http://moodle.org/mod/forum/discuss.php?d=152369
Source: CCN Type: SA40248 Moodle Multiple Vulnerabilities
Source: SECUNIA Type: Vendor Advisory 40248
Source: SECUNIA Type: Vendor Advisory 40352
Source: CONFIRM Type: UNKNOWN http://tracker.moodle.org/browse/MDL-21688
Source: DEBIAN Type: DSA-2115 moodle -- several vulnerabilities
Source: MLIST Type: UNKNOWN [oss-security] 20100621 Re: CVE request: moodle 1.9.9/1.8.13 multiple vulnerabilities
Source: CCN Type: OSVDB ID: 65637 Moodle report/overview/report.php attemptid Parameter Quiz Report Deletion CSRF
Source: CCN Type: BID-40944 Moodle Multiple Vulnerabilities
Source: VUPEN Type: Patch, Vendor Advisory ADV-2010-1530
Source: VUPEN Type: Vendor Advisory ADV-2010-1571
Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=605809
Source: XF Type: UNKNOWN moodle-unspecified-csrf(59546)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5:-:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.1.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:*:*:*:*:*:*:*:* (Version <= 1.8.12)OR cpe:/a:moodle:moodle:1.8.11:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5.0:beta:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.8:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.10:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.9:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.2.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.2.0:*:*:*:*:*:*:* Configuration 2: cpe:/a:moodle:moodle:1.9.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.8:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.5:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:moodle:moodle:1.9.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.11:*:*:*:*:*:*:*AND cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |