CVE-2011-4281: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4281?
CVE-2011-4281 is a medium severity vulnerability, as it allows remote attackers to hijack user authentication through CSRF.
How do I fix CVE-2011-4281?
To fix CVE-2011-4281, update Moodle to version 2.0.2 or later where the vulnerabilities have been addressed.
What types of attacks are possible with CVE-2011-4281?
CVE-2011-4281 allows attackers to perform cross-site request forgery attacks, potentially manipulating user actions without their consent.
Which versions of Moodle are affected by CVE-2011-4281?
CVE-2011-4281 affects Moodle versions 2.0.0 and 2.0.1.
What are the consequences of exploiting CVE-2011-4281?
Exploitation of CVE-2011-4281 could lead to unauthorized changes in course or activity completions, impacting user data integrity.