Description
The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.
Remediation
References
Related Vulnerabilities
WordPress Plugin Uploadify Integration Multiple Cross-Site Scripting Vulnerabilities (0.9.6)
WordPress Plugin WordPress Poll Cross-Site Request Forgery (34.05)
WordPress Plugin eHive Object Details Cross-Site Scripting (2.1.6)
WordPress Plugin Easy Forms for MailChimp Unspecified Vulnerability (6.0.3.2)