Cross-Site Request Forgery Vulnerability in Moodle by Moodle.org
CVE-2017-7491
4.3MEDIUM
Summary
In Moodle versions 2.x and 3.x, a vulnerability exists that allows an attacker to exploit cross-site request forgery techniques. This security issue enables unauthorized changes to the configuration setting for the number of courses displayed in the course overview block. Attackers can potentially manipulate user preferences without their consent, highlighting the need for prompt updates and robust security practices within Moodle installations.
Affected Version(s)
Moodle 2.x and 3.x Moodle 2.x and 3.x
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved