Candidate: CVE-2011-4281 PublicDate: 2012-07-16 10:28:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4281 Description: Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course. Ubuntu-Description: Notes: jdstrand> moodle 2.0 only Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_moodle: upstream_moodle: needs-triage hardy_moodle: ignored (reached end-of-life) lucid_moodle: not-affected maverick_moodle: not-affected natty_moodle: not-affected oneiric_moodle: not-affected devel_moodle: not-affected (1.9.9.dfsg2-4)