CVE-2014-7838 PUBLISHED CVSS 6.800000190734863 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

EPSS 0.17% · 38.6th percentile

Risk Scores

CVSS v2.0
6.800000190734863
EPSS Score
0.17%
38.6th percentile

Affected Products

VendorProductVersions
n/an/an/a
moodlemoodle0, 2.6.0, 2.7.0
moodlemoodle0, 2.5.0, 2.5.1

Timeline

References

…and 2 more

Open in Interactive Console →