Security Advisory

CVE-2009-4300

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-12-16 01:00:00
Last updated 2024-09-17 03:13:36
Assigner mitre
State PUBLISHED

Description

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.