CVE-2011-4585: Medium severity moodle vulnerability
Published Jul 20, 2012
·Updated
login/changepassword.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.
Affected Software
14 affected components
Moodle moodle=1.9.4
Moodle moodle=1.9.1
Moodle moodle=1.9.6
Moodle moodle=1.9.9
Moodle moodle=1.9.11
Moodle moodle=1.9.2
Moodle moodle=1.9.12
Moodle moodle=1.9.10
Moodle moodle=1.9.3
Moodle moodle=1.9.13
Moodle moodle=1.9.5
Moodle moodle=1.9.14
Moodle moodle=1.9.8
Moodle moodle=1.9.7
Event History
Jul 20, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4585?
CVE-2011-4585 is considered a high-severity vulnerability due to the potential for credential theft.
2
How do I fix CVE-2011-4585?
To fix CVE-2011-4585, ensure that your Moodle version is updated to 1.9.15 or later.
3
What does CVE-2011-4585 exploit?
CVE-2011-4585 exploits the lack of HTTPS usage for the change-password form in affected Moodle versions.
4
Which versions of Moodle are affected by CVE-2011-4585?
CVE-2011-4585 affects Moodle versions 1.9.x prior to 1.9.15, including 1.9.1 to 1.9.14.
5
Can I utilize HTTPS with my current Moodle installation to mitigate CVE-2011-4585?
Unfortunately, enabling the httpslogin option does not mitigate CVE-2011-4585 in the affected versions, so upgrading is necessary.