7.5
CVSSv2

CVE-2009-4304

Published: 16/12/2009 Updated: 01/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Moodle 1.8 prior to 1.8.11 and 1.9 prior to 1.9.7 does not use a random password salt in config.php, which makes it easier for malicious users to conduct brute-force password guessing attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 1.8.1

moodle moodle 1.8.2

moodle moodle 1.8.3

moodle moodle 1.8.4

moodle moodle 1.8.10

moodle moodle 1.9.1

moodle moodle 1.9.2

moodle moodle 1.8.7

moodle moodle 1.8.9

moodle moodle 1.9.3

moodle moodle 1.9.5

moodle moodle 1.8.5

moodle moodle 1.8.8

moodle moodle 1.9.4

moodle moodle 1.9.6