First published: Wed Jul 11 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =2.0.0 | |
Moodle | =2.0.1 | |
Moodle | =2.0.2 | |
Moodle | =2.0.3 | |
Moodle | =2.0.4 | |
Moodle | =2.1.0 | |
Moodle | =2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4298 has a medium severity rating due to its potential to allow attackers to hijack user authentication.
To fix CVE-2011-4298, update your Moodle installation to version 2.0.5 or 2.1.2 or later.
CVE-2011-4298 affects Moodle versions prior to 2.0.5 and 2.1.2, including all 2.0.x and 2.1.x versions before these updates.
CVE-2011-4298 allows attackers to perform cross-site request forgery (CSRF) attacks that can modify wiki data.
Yes, user data is at risk as CVE-2011-4298 can lead to unauthorized modifications of wiki content by hijacking user sessions.