CVE-2009-4302

Moodle 1.8 <1.8.11-1.9 <1.9.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

References (9)

Core 9
Core References
Patch, Vendor Advisory x_refsource_confirm
http://moodle.org/mod/forum/discuss.php?d=139107
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3455
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37614
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37244

Scores

EPSS 0.0089
EPSS Percentile 75.8%

Details

CWE
CWE-310
Status published
Products (15)
moodle/moodle 1.8.1
moodle/moodle 1.8.2
moodle/moodle 1.8.3
moodle/moodle 1.8.4
moodle/moodle 1.8.5
moodle/moodle 1.8.7
moodle/moodle 1.8.8
moodle/moodle 1.8.9
moodle/moodle 1.8.10
moodle/moodle 1.9.1
... and 5 more
Published Dec 16, 2009
Tracked Since Feb 18, 2026