UBUNTU-CVE-2012-6103

Source
https://ubuntu.com/security/CVE-2012-6103
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-6103.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-6103
Upstream
  • CVE-2012-6103
Withdrawn
2025-07-18T16:42:48Z
Published
2013-01-27T22:55:00Z
Modified
2025-07-16T07:31:04.144306Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

References

Affected packages

Ubuntu:14.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle@2.5.4-1ubuntu1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.4-1ubuntu1

Affected versions

2.*
2.5.2-1
2.5.3-1
2.5.3-2
2.5.3-3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.5.4-1ubuntu1",
            "binary_name": "moodle"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-6103.json"