Cross-Site Request Forgery Vulnerability in Moodle by Moodle.org
CVE-2017-7491

4.3MEDIUM

Key Information:

Vendor
Moodle
Vendor
CVE Published:
15 May 2017

Summary

In Moodle versions 2.x and 3.x, a vulnerability exists that allows an attacker to exploit cross-site request forgery techniques. This security issue enables unauthorized changes to the configuration setting for the number of courses displayed in the course overview block. Attackers can potentially manipulate user preferences without their consent, highlighting the need for prompt updates and robust security practices within Moodle installations.

Affected Version(s)

Moodle 2.x and 3.x Moodle 2.x and 3.x

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.