CVE-2010-2231

NameCVE-2010-2231
DescriptionCross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid parameter.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2115-1
NVD severitymedium (attack range: remote, user-initiated)
Debian Bugs586280
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot known to be vulnerable.
Debian/stablenot known to be vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
moodle (PTS)squeeze1.9.9.dfsg2-2.1+squeeze4fixed
squeeze (security)1.9.9.dfsg2-2.1+squeeze3fixed
sid2.7.8+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
moodlesource(unstable)1.9.9-1medium586280
moodlesourcelenny1.8.13-1mediumDSA-2115-1

Search for package or bug name: Reporting problems