CVE-2009-4304: High severity moodle vulnerability
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4304?
CVE-2009-4304 is considered a medium severity vulnerability due to its potential for brute-force password guessing attacks.
How do I fix CVE-2009-4304?
To fix CVE-2009-4304, upgrade Moodle to version 1.8.11 or 1.9.7 or later, which includes the necessary improvements for password security.
Which versions of Moodle are affected by CVE-2009-4304?
CVE-2009-4304 affects Moodle versions 1.8 before 1.8.11 and 1.9 before 1.9.7.
What are the risks associated with CVE-2009-4304?
The primary risk associated with CVE-2009-4304 is that attackers can exploit the lack of a random password salt to conduct successful brute-force attacks.
Can I mitigate CVE-2009-4304 without upgrading?
Mitigating CVE-2009-4304 without upgrading is challenging, but implementing strong password policies may help reduce the risk of successful brute-force attacks.