Description
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
Remediation
References
Related Vulnerabilities
WordPress Plugin Media Library Assistant SQL Injection (2.84)
WordPress Plugin HTML5 MP3 Player with Playlist Free Information Disclosure (2.6)
WordPress Plugin FL3R FeelBox Multiple Vulnerabilities (8.1)
Joomla! Core 3.x.x Security Bypass (3.8.13 - 3.9.6)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-1648)