5
CVSSv2

CVE-2012-2357

Published: 21/07/2012 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x prior to 2.1.6 and 2.2.x prior to 2.2.3 does not use HTTPS, which allows remote malicious users to obtain credentials by sniffing the network.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.1.2

moodle moodle 2.1.1

moodle moodle 2.1.5

moodle moodle 2.1.3

moodle moodle 2.1.4

moodle moodle 2.1.0

moodle moodle 2.2.2

moodle moodle 2.2.1

moodle moodle 2.2.0