First published: Thu Apr 20 2017(Updated: )
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | =2.7.0 | |
Moodle Moodle | =2.7.0-beta | |
Moodle Moodle | =2.7.0-rc1 | |
Moodle Moodle | =2.7.0-rc2 | |
Moodle Moodle | =2.7.1 | |
Moodle Moodle | =2.7.2 | |
Moodle Moodle | =2.7.3 | |
Moodle Moodle | =2.7.4 | |
Moodle Moodle | =2.7.5 | |
Moodle Moodle | =2.7.6 | |
Moodle Moodle | =2.7.7 | |
Moodle Moodle | =2.7.8 | |
Moodle Moodle | =2.7.9 | |
Moodle Moodle | =2.7.10 | |
Moodle Moodle | =2.7.11 | |
Moodle Moodle | =2.7.12 | |
Moodle Moodle | =2.7.13 | |
Moodle Moodle | =2.8.0 | |
Moodle Moodle | =2.8.1 | |
Moodle Moodle | =2.8.2 | |
Moodle Moodle | =2.8.3 | |
Moodle Moodle | =2.8.4 | |
Moodle Moodle | =2.8.5 | |
Moodle Moodle | =2.8.6 | |
Moodle Moodle | =2.8.7 | |
Moodle Moodle | =2.8.8 | |
Moodle Moodle | =2.8.9 | |
Moodle Moodle | =2.8.10 | |
Moodle Moodle | =2.8.11 | |
Moodle Moodle | =2.9.0 | |
Moodle Moodle | =2.9.1 | |
Moodle Moodle | =2.9.2 | |
Moodle Moodle | =2.9.3 | |
Moodle Moodle | =2.9.4 | |
Moodle Moodle | =2.9.5 | |
Moodle Moodle | =3.0.0 | |
Moodle Moodle | =3.0.0-beta | |
Moodle Moodle | =3.0.0-rc1 | |
Moodle Moodle | =3.0.0-rc2 | |
Moodle Moodle | =3.0.0-rc3 | |
Moodle Moodle | =3.0.0-rc4 | |
Moodle Moodle | =3.0.1 | |
Moodle Moodle | =3.0.2 | |
Moodle Moodle | =3.0.3 | |
composer/moodle/moodle | >=3.0<3.0.4 | 3.0.4 |
composer/moodle/moodle | >=2.9<2.9.6 | 2.9.6 |
composer/moodle/moodle | >=2.8<2.8.12 | 2.8.12 |
composer/moodle/moodle | <2.7.14 | 2.7.14 |
=2.7.0 | ||
=2.7.0-beta | ||
=2.7.0-rc1 | ||
=2.7.0-rc2 | ||
=2.7.1 | ||
=2.7.2 | ||
=2.7.3 | ||
=2.7.4 | ||
=2.7.5 | ||
=2.7.6 | ||
=2.7.7 | ||
=2.7.8 | ||
=2.7.9 | ||
=2.7.10 | ||
=2.7.11 | ||
=2.7.12 | ||
=2.7.13 | ||
=2.8.0 | ||
=2.8.1 | ||
=2.8.2 | ||
=2.8.3 | ||
=2.8.4 | ||
=2.8.5 | ||
=2.8.6 | ||
=2.8.7 | ||
=2.8.8 | ||
=2.8.9 | ||
=2.8.10 | ||
=2.8.11 | ||
=2.9.0 | ||
=2.9.1 | ||
=2.9.2 | ||
=2.9.3 | ||
=2.9.4 | ||
=2.9.5 | ||
=3.0.0 | ||
=3.0.0-beta | ||
=3.0.0-rc1 | ||
=3.0.0-rc2 | ||
=3.0.0-rc3 | ||
=3.0.0-rc4 | ||
=3.0.1 | ||
=3.0.2 | ||
=3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.