CVE-2016-3734

high

Description

Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1335933

http://www.securitytracker.com/id/1035902

http://www.securityfocus.com/bid/91281

http://www.openwall.com/lists/oss-security/2016/05/17/4

http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53755

Details

Source: Mitre, NVD

Published: 2017-04-20

Updated: 2020-12-01

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High