Weak Password Recovery Mechanism for Forgotten Password in Moodle



Published: 2017-01-20 | Updated: 2020-08-08
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2016-7038
CWE-ID CWE-640
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Moodle
Web applications / Other software

Vendor moodle.org

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Weak Password Recovery Mechanism for Forgotten Password

EUVDB-ID: #VU39808

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-7038

CWE-ID: CWE-640 - Weak password recovery mechanism

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Moodle: 2.8 - 3.1.1

External links

http://www.securityfocus.com/bid/93174
http://moodle.org/mod/forum/discuss.php?d=339631


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###