6
CVSSv2

CVE-2008-3325

Published: 25/07/2008 Updated: 01/11/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x prior to 1.6.7 and 1.7.x prior to 1.7.5 allows remote malicious users to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle

debian debian linux 4.0

Vendor Advisories

Several remote vulnerabilities have been discovered in Moodle, an online course management system The following issues are addressed in this update, ranging from cross site scripting to remote code execution Various cross site scripting issues in the Moodle codebase (CVE-2008-3326, CVE-2008-3325, CVE-2007-3555, CVE-2008-5432, MSA-08-0021, MDL-884 ...