VDB
CVE-2014-7838
CVE-2014-7838
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.
EPSS 0.17% · 38.6th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
0.17%
38.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| moodle | moodle | 0, 2.7.0, 2.6.0 |
| moodle | moodle | 2.5.3, 2.5.4, 2.5.5 |
Exploit Intelligence
Timeline
- Nov 17, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- https://moodle.org/mod/forum/discuss.php?d=275161 advisory
- https://moodle.org/mod/forum/discuss.php?d=275147 advisory
- https://moodle.org/mod/forum/discuss.php?d=275155 advisory
- https://moodle.org/mod/forum/discuss.php?d=275159 advisory
- https://moodle.org/mod/forum/discuss.php?d=275158 advisory
- https://moodle.org/mod/forum/discuss.php?d=275163 advisory
- https://moodle.org/mod/forum/discuss.php?d=275153 advisory
- https://moodle.org/mod/forum/discuss.php?d=275165 advisory
- https://moodle.org/mod/forum/discuss.php?d=275162 advisory
- https://moodle.org/mod/forum/discuss.php?d=275154 advisory
- https://moodle.org/mod/forum/discuss.php?d=275164 advisory
- https://moodle.org/mod/forum/discuss.php?d=275157 advisory
- 1031215 vdb
- [oss-security] 20141117 Moodle security issues are now public mailing-list
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-48019 url
- https://nvd.nist.gov/vuln/detail/CVE-2014-7838 advisory
- https://github.com/moodle/moodle/commit/545eb1bcfdbfc352bf6c31edf440485ba6d5af42 url
- https://github.com/moodle/moodle/commit/7a311adbba9471edb5a49e4c4b8c356c87f0e44b url
- https://github.com/moodle/moodle/commit/bef4a5e01739f2b239c0910b9e1aa2841b979f7d url
- https://github.com/moodle/moodle/commit/c812956efda7d10dfdce5ae19c0ec8879de38a31 url
…and 2 more