CVE-2008-3325
Debian Linux Security Advisory 1691-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.
Vulnerabilidad de falsificación de petición en sitios cruzados (CSFR) en Moodle 1.6.x versiones anteriores a la 1.6.7 y 1.7.x versiones anteriores a la 1.7.5, permite a atacantes remotos modificar el perfil de la configuración y obtener privilegios como otro usuario a través de un enlace o etiqueta IMG de la página de edición del perfil de usuario.
Several remote vulnerabilities have been discovered in Moodle, an online course management system. The following issues are addressed in this update, ranging from cross site scripting to remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-07-25 CVE Reserved
- 2008-07-25 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/31196 | Third Party Advisory | |
http://secunia.com/advisories/31339 | Third Party Advisory | |
http://www.procheckup.com/Vulnerability_PR08-16.php | Broken Link | |
http://www.securityfocus.com/archive/1/494658/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43964 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://moodle.org/mod/forum/discuss.php?d=101405 | 2018-11-01 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html | 2018-11-01 | |
http://www.debian.org/security/2008/dsa-1691 | 2018-11-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | >= 1.6 < 1.6.7 Search vendor "Moodle" for product "Moodle" and version " >= 1.6 < 1.6.7" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | >= 1.7 < 1.7.5 Search vendor "Moodle" for product "Moodle" and version " >= 1.7 < 1.7.5" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 4.0 Search vendor "Debian" for product "Debian Linux" and version "4.0" | - |
Affected
|