Credentials management in Moodle - CVE-2011-4587

 

Credentials management in Moodle - CVE-2011-4587

Published: July 20, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43837
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4587
CWE-ID: CWE-255
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2011-4587

Install update from vendor's website.

moodle - update to 2.1.3-1.el6

External References

Related Security Bulletins