DescriptionCross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid parameter.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
SUSE Security Advisories:
- SUSE-SR:2010:014, published Mon, 02 Aug 2010 15:00:00 +0000
- openSUSE-SU-2010:0365-1, published Mon, 12 Jul 2010 18:08:09 +0200 (CEST)
SUSE Timeline for this CVECVE page created: Fri Jun 28 07:26:04 2013
CVE page last modified: Fri Oct 7 12:45:56 2022