First published: Tue Feb 10 2009(Updated: )
Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive information and conduct "brute force attacks on user accounts" via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.9.1 | |
Moodle | =1.8.2 | |
Moodle | =1.9.2 | |
Moodle | =1.8.6 | |
Moodle | =1.8.5 | |
Moodle | =1.8.3 | |
Moodle | =1.8.7 | |
Moodle | =1.9.3 | |
Moodle | =1.8.4 | |
Moodle | =1.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0501 is classified as a medium-severity vulnerability due to the potential for sensitive information disclosure and brute force attacks on user accounts.
To fix CVE-2009-0501, you should upgrade your Moodle installation to version 1.8.8 or later for 1.8 series and to version 1.9.4 or later for 1.9 series.
CVE-2009-0501 affects Moodle versions 1.8.1 to 1.8.7 and 1.9.1 to 1.9.3.
CVE-2009-0501 can enable attackers to conduct brute force attacks on user accounts and potentially obtain sensitive information.
There are no specific workarounds for CVE-2009-0501; the best mitigation is to update to a patched version of Moodle.