Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffr2-q8c8-w5xj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

EPSS

Процентиль: 59%
0.00388
Низкий

Связанные уязвимости

ubuntu
почти 13 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

nvd
почти 13 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

debian
почти 13 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use h ...

EPSS

Процентиль: 59%
0.00388
Низкий