Vulnerability Name: | CVE-2012-6103 (CCN-81446) |
Assigned: | 2012-12-06 |
Published: | 2013-01-15 |
Updated: | 2020-12-01 |
Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-352
|
Vulnerability Consequences: | Cross-Site Scripting |
References: | Source: MITRE Type: CNA CVE-2012-6103
Source: CONFIRM Type: UNKNOWN http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36600
Source: MLIST Type: UNKNOWN [oss-security] 20130121 Moodle security notifications public
Source: CCN Type: SA51842 Moodle Multiple Vulnerabilities
Source: XF Type: UNKNOWN moodle-message-messageselect-csrf(81446)
Source: CCN Type: Moodle Web Site Moodle
Source: CCN Type: MSA-13-0007 Potential exploit in messaging
Source: CONFIRM Type: Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=220164
|
Vulnerable Configuration: | Configuration 1: cpe:/a:moodle:moodle:2.2.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.4:*:*:*:*:*:*:* Configuration 2: cpe:/a:moodle:moodle:2.3.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.3.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.3.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.3.0:*:*:*:*:*:*:* Configuration 3: cpe:/a:moodle:moodle:2.4.0:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:moodle:moodle:2.2.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.3.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.3.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.3.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.3.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.4.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:2.2.6:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |