Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.
2012-07-16T10:28:36.207
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | moodle | moodle | 1.9.1 | Yes |
| Application | moodle | moodle | 1.9.2 | Yes |
| Application | moodle | moodle | 1.9.3 | Yes |
| Application | moodle | moodle | 1.9.4 | Yes |
| Application | moodle | moodle | 1.9.5 | Yes |
| Application | moodle | moodle | 1.9.6 | Yes |
| Application | moodle | moodle | 1.9.7 | Yes |
| Application | moodle | moodle | 1.9.8 | Yes |
| Application | moodle | moodle | 1.9.9 | Yes |
| Application | moodle | moodle | 1.9.10 | Yes |