CVE-2014-7845: High severity moodle vulnerability
The generatepassword function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7845?
CVE-2014-7845 has a medium severity rating as it allows remote attackers to gain unauthorized access via brute-force attacks.
How do I fix CVE-2014-7845?
To fix CVE-2014-7845, upgrade to Moodle version 2.5.9, 2.6.6, or 2.7.3 or later.
Which versions of Moodle are affected by CVE-2014-7845?
CVE-2014-7845 affects Moodle versions up to 2.4.11 and specific versions of 2.5.x, 2.6.x, and 2.7.x.
What happens if I don't resolve CVE-2014-7845?
If CVE-2014-7845 is not resolved, your Moodle installation may be vulnerable to brute-force attacks allowing unauthorized access.
Is there a workaround for CVE-2014-7845?
There are no official workarounds for CVE-2014-7845; updating to a patched version is the recommended action.