CVE-2008-3325: CSRF
Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3325?
CVE-2008-3325 is considered a medium severity vulnerability due to its ability to allow attackers to modify user settings.
How do I fix CVE-2008-3325?
To fix CVE-2008-3325, upgrade Moodle to at least version 1.6.7 or 1.7.5 or later where the vulnerability has been patched.
What impact does CVE-2008-3325 have on Moodle users?
CVE-2008-3325 allows attackers to change profile settings and gain unauthorized privileges as other users.
Which versions of Moodle are affected by CVE-2008-3325?
Moodle versions 1.6.x prior to 1.6.7 and 1.7.x prior to 1.7.5 are affected by CVE-2008-3325.
Can Debian systems be impacted by CVE-2008-3325?
Yes, the Debian GNU/Linux 4.0 version is also susceptible to CVE-2008-3325 if it runs an affected version of Moodle.