CVE-2015-0213: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0213?
CVE-2015-0213 has a medium severity rating due to its potential for cross-site request forgery (CSRF) attacks.
How do I fix CVE-2015-0213?
To fix CVE-2015-0213, update Moodle to versions 2.8.2, 2.7.4, or 2.6.7 or later.
What versions of Moodle are affected by CVE-2015-0213?
CVE-2015-0213 affects Moodle versions up to 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2.
What types of attacks does CVE-2015-0213 enable?
CVE-2015-0213 enables remote attackers to hijack user authentication through CSRF vulnerabilities.
Is it safe to continue using an affected version of Moodle after CVE-2015-0213 is identified?
It is not safe to use affected versions of Moodle without applying the necessary updates after identifying CVE-2015-0213.