Description
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2024 | In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. |
Github GHSA |
GHSA-2phx-w35g-x9vm | Moodle Weak Password Recovery Mechanism for Forgotten Password |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T01:50:46.881Z
Reserved: 2016-08-23T00:00:00.000Z
Link: CVE-2016-7038
No data.
Status : Deferred
Published: 2017-01-20T08:59:00.283
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-7038
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA