cbcvebase.
CVE-2008-3325
published 2008-07-25

CVE-2008-3325: Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain…

PriorityP423medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.06%
61.3th percentile
Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

Affected

3 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
moodlemoodle>= 1.6 < 1.6.71.6.7
moodlemoodle>= 1.7 < 1.7.51.7.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.