First published: Thu Apr 29 2010(Updated: )
Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.9.4 | |
Moodle | =1.9.1 | |
Moodle | =1.8.8 | |
Moodle | =1.9.6 | |
Moodle | =1.8.2 | |
Moodle | =1.9.2 | |
Moodle | =1.8.6 | |
Moodle | =1.8.5 | |
Moodle | =1.8.3 | |
Moodle | =1.8.9 | |
Moodle | =1.8.7 | |
Moodle | =1.8.10 | |
Moodle | =1.9.3 | |
Moodle | =1.9.5 | |
Moodle | =1.8.11 | |
Moodle | =1.8.4 | |
Moodle | =1.8.1 | |
Moodle | =1.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1613 is categorized as a medium severity vulnerability.
To fix CVE-2010-1613, ensure that the 'Regenerate session id during login' setting is enabled in your Moodle configuration.
Moodle versions 1.8.x and 1.9.x prior to 1.9.8 are affected by CVE-2010-1613.
CVE-2010-1613 is associated with session fixation attacks, which can compromise user sessions.
Yes, a patch is included in Moodle version 1.9.8 and later, addressing CVE-2010-1613.