CVE-2009-0499

EUVD-2009-0503
Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
moodlemoodle
1.7.1
moodlemoodle
1.7.2
moodlemoodle
1.7.3
moodlemoodle
1.7.4
moodlemoodle
1.7.5
moodlemoodle
1.7.6
moodlemoodle
1.8.1
moodlemoodle
1.8.2
moodlemoodle
1.8.3
moodlemoodle
1.8.4
moodlemoodle
1.8.5
moodlemoodle
1.8.6
moodlemoodle
1.8.7
moodlemoodle
1.9.1
moodlemoodle
1.9.2
moodlemoodle
1.9.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
moodle
dapper
ignored
gutsy
ignored
hardy
Fixed 1.8.2-1ubuntu4.2
released
intrepid
Fixed 1.8.2-1.2ubuntu2.1
released
jaunty
not-affected
karmic
not-affected