CVE-2015-0218: CSRF
Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0218?
CVE-2015-0218 has been classified as a moderate severity vulnerability, enabling attackers to hijack user authentication.
How do I fix CVE-2015-0218?
To fix CVE-2015-0218, upgrade to Moodle version 2.8.2, 2.7.4, or 2.6.7 or later.
What versions of Moodle are affected by CVE-2015-0218?
CVE-2015-0218 affects Moodle versions 2.5.9 and earlier, all 2.6.x versions before 2.6.7, all 2.7.x versions before 2.7.4, and 2.8.x versions before 2.8.2.
What is a Cross-Site Request Forgery (CSRF) vulnerability in CVE-2015-0218?
In the context of CVE-2015-0218, a CSRF vulnerability allows attackers to trick users into executing unwanted actions on a web application in which they're authenticated.
Who is impacted by the CVE-2015-0218 vulnerability?
Users and administrators of affected Moodle versions are at risk of having their authentication compromised by unauthorized logout requests.