Описание
Moodle Weak Password Recovery Mechanism for Forgotten Password
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
Пакеты
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 2.7, < 2.7.16
2.7.16
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 2.9, < 2.9.8
2.9.8
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 3.0, < 3.0.6
3.0.6
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 3.1, < 3.1.2
3.1.2
Связанные уязвимости
CVSS3: 7.3
ubuntu
больше 8 лет назад
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CVSS3: 7.3
nvd
больше 8 лет назад
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CVSS3: 7.3
debian
больше 8 лет назад
In Moodle 2.x and 3.x, web service tokens are not invalidated when the ...