Beveiligingsadvies
CVE-2012-6103
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.