CVE-2009-4300

Moodle <1.8.11-1.9.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.

References (9)

Core 9
Core References
Various Sources x_refsource_confirm
http://moodle.org/mod/forum/discuss.php?d=139105
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3455
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37614
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37244

Scores

EPSS 0.0059
EPSS Percentile 69.4%

Details

CWE
CWE-200
Status published
Products (15)
moodle/moodle 1.8.1
moodle/moodle 1.8.2
moodle/moodle 1.8.3
moodle/moodle 1.8.4
moodle/moodle 1.8.5
moodle/moodle 1.8.7
moodle/moodle 1.8.8
moodle/moodle 1.8.9
moodle/moodle 1.8.10
moodle/moodle 1.9.1
... and 5 more
Published Dec 16, 2009
Tracked Since Feb 18, 2026