CVE-2012-6103: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6103?
CVE-2012-6103 has a moderate severity level due to its potential for cross-site request forgery effects.
How do I fix CVE-2012-6103?
To fix CVE-2012-6103, upgrade Moodle to versions 2.2.7, 2.3.4, or 2.4.1 or later.
Which versions of Moodle are affected by CVE-2012-6103?
CVE-2012-6103 affects Moodle versions 2.2.0 to 2.2.6, 2.3.0 to 2.3.3, and 2.4.0.
What types of attacks can CVE-2012-6103 facilitate?
CVE-2012-6103 can facilitate attacks that hijack the authentication of users sending course messages through CSRF.
Is user data at risk due to CVE-2012-6103?
Yes, user data is at risk as attackers can potentially send unauthorized course messages impersonating legitimate users.