Moodle 'enrol/imsenterprise/importnow.php' Cross Site Request Forgery Vulnerability
BID:66335
Info
Moodle 'enrol/imsenterprise/importnow.php' Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 66335 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0126 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2014 12:00AM |
| Updated: | May 07 2015 05:08PM |
| Credit: | Tyler William Thomas |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Moodle 'enrol/imsenterprise/importnow.php' Cross Site Request Forgery Vulnerability
Moodle is prone to a cross-site request-forgery vulnerability because it does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks.
Moodle versions 2.6 through 2.6.1, 2.5 through 2.5.4, and 2.4 through 2.4.8 are vulnerable.
Moodle is prone to a cross-site request-forgery vulnerability because it does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks.
Moodle versions 2.6 through 2.6.1, 2.5 through 2.5.4, and 2.4 through 2.4.8 are vulnerable.
Exploit / POC
Moodle 'enrol/imsenterprise/importnow.php' Cross Site Request Forgery Vulnerability
To exploit this issue the attacker needs to entice a user into following a malicious URI.
To exploit this issue the attacker needs to entice a user into following a malicious URI.
Solution / Fix
Moodle 'enrol/imsenterprise/importnow.php' Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Moodle 'enrol/imsenterprise/importnow.php' Cross Site Request Forgery Vulnerability
References:
References: