Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-12-16T01:00:00Z
Updated: 2024-09-17T03:13:36.447Z
Reserved: 2009-12-11T00:00:00Z
Link: CVE-2009-4300
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-12-16T01:30:00.407
Modified: 2024-11-21T01:09:18.900
Link: CVE-2009-4300
Redhat