CVE-2010-1613

Publication date

2010-04-29 21:00:00

Family

mitre

State

PUBLISHED

Description

Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.