Vulnerability Name: | CVE-2012-6103 (CCN-81446) | ||||||||||||
Assigned: | 2012-12-06 | ||||||||||||
Published: | 2013-01-15 | ||||||||||||
Updated: | 2020-12-01 | ||||||||||||
Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-352 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-6103 Source: CONFIRM Type: UNKNOWN http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36600 Source: MLIST Type: UNKNOWN [oss-security] 20130121 Moodle security notifications public Source: CCN Type: SA51842 Moodle Multiple Vulnerabilities Source: XF Type: UNKNOWN moodle-message-messageselect-csrf(81446) Source: CCN Type: Moodle Web Site Moodle Source: CCN Type: MSA-13-0007 Potential exploit in messaging Source: CONFIRM Type: Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=220164 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |