CVE-2016-3734: CSRF
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3734?
CVE-2016-3734 has a medium severity level due to its potential for allowing unauthorized actions through CSRF vulnerabilities.
How do I fix CVE-2016-3734?
To fix CVE-2016-3734, upgrade your Moodle installation to versions 2.7.14, 2.8.12, 2.9.6, or 3.0.4 or later.
What versions of Moodle are affected by CVE-2016-3734?
CVE-2016-3734 affects Moodle versions 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, and 2.7 through 2.7.13.
Can CVE-2016-3734 be exploited remotely?
Yes, CVE-2016-3734 can be exploited remotely by attackers to hijack user authentication for marking forum posts as read.
What is a Cross-site Request Forgery vulnerability as seen in CVE-2016-3734?
A Cross-site Request Forgery vulnerability, like CVE-2016-3734, allows attackers to perform actions on behalf of an authenticated user without their consent.