In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.0-beta"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.12"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.13"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.14"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.15"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.16"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.17"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.18"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-beta"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-rc4"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.5"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.8"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0-beta"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-beta"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-rc4"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-rc5"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.2"
}
]
}