Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.Referenceshttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://cvs.moodle.org/moodle/mod/forum/post.php?r1=1.154.2.14&r2=1.154.2.15http://moodle.org/security/http://secunia.com/advisories/34418http://www.openwall.com/lists/oss-security/2009/02/04/1