lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2012-07-20T10:00:00
Updated: 2024-08-07T00:09:19.404Z
Reserved: 2011-11-29T00:00:00
Link: CVE-2011-4587
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-07-20T10:40:35.970
Modified: 2024-11-21T01:32:36.540
Link: CVE-2011-4587
Redhat
No data.