Vulnerability Name: | CVE-2011-4133 (CCN-77688) | ||||||||
Assigned: | 2011-11-13 | ||||||||
Published: | 2011-11-13 | ||||||||
Updated: | 2020-12-01 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-4133 Source: CONFIRM Type: UNKNOWN http://git.moodle.org/gw?p=moodle.git;a=commit;h=8f031d5431c1204197b1482fd6c63bc87a19a476 Source: CCN Type: Moodle Web Site Moodle.org: open-source community-based tools for learning Source: CCN Type: MSA-11-0002 Cross-site request forgery vulnerability in RSS block Source: CONFIRM Type: Vendor Advisory http://moodle.org/mod/forum/discuss.php?d=170002 Source: MLIST Type: UNKNOWN [oss-security] 20111113 Re: Fwd: DSA 2338-1 moodle security update Source: CCN Type: OSVDB ID: 75056 Moodle Multiple Function CSRF Source: XF Type: UNKNOWN moodle-rss-csrf(77688) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |