Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.
http://www.openwall.com/lists/oss-security/2009/02/04/1
http://secunia.com/advisories/34418
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
http://cvs.moodle.org/moodle/mod/forum/post.php?r1=1.154.2.14&r2=1.154.2.15