CVE-2009-4300
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
16/12/2009
Last modified:
09/04/2025
Description
Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:moodle:moodle:1.8.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.8.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.9.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.9.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.9.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.9.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.9.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:1.9.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://docs.moodle.org/en/Moodle_1.8.11_release_notes
- http://docs.moodle.org/en/Moodle_1.9.7_release_notes
- http://moodle.org/mod/forum/discuss.php?d=139105
- http://secunia.com/advisories/37614
- http://www.securityfocus.com/bid/37244
- http://www.vupen.com/english/advisories/2009/3455
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html
- http://docs.moodle.org/en/Moodle_1.8.11_release_notes
- http://docs.moodle.org/en/Moodle_1.9.7_release_notes
- http://moodle.org/mod/forum/discuss.php?d=139105
- http://secunia.com/advisories/37614
- http://www.securityfocus.com/bid/37244
- http://www.vupen.com/english/advisories/2009/3455
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html



