Description
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
Remediation
References
Related Vulnerabilities
PHP Address Book Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-2778)
Joomla! Core 3.3.x Denial of Service (3.3.0 - 3.3.4)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-39112)
WordPress Plugin WP Keyword Link Multiple Cross-Site Scripting Vulnerabilities (1.7)