CVE-2009-4300: Infoleak
Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4300?
CVE-2009-4300 has a medium severity due to the potential exposure of user credentials.
How do I fix CVE-2009-4300?
To fix CVE-2009-4300, upgrade Moodle to version 1.8.11 or 1.9.7 or later.
Which versions are affected by CVE-2009-4300?
CVE-2009-4300 affects Moodle versions 1.8.x before 1.8.11 and 1.9.x before 1.9.7.
What are the implications of CVE-2009-4300?
The implications of CVE-2009-4300 include potential unauthorized access to user accounts through compromised password hashes.
Is there a patch available for CVE-2009-4300?
Yes, upgrading to the patched versions of Moodle will resolve the vulnerabilities outlined in CVE-2009-4300.