Description
Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid parameter.
Remediation
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-2138)
WordPress Use of Insufficiently Random Values Vulnerability (CVE-2017-17091)
Roundcube Multiple Buffer Overflow Vulnerabilities (CVE-2015-2181)
WordPress Plugin Orbit Fox by ThemeIsle Multiple Vulnerabilities (2.10.2)