Описание
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 2.2.2.dfsg-2 |
esm-apps/xenial | not-affected | 2.2.2.dfsg-2 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [2.2.2.dfsg-2]] |
hardy | ignored | end of life |
lucid | ignored | end of life |
maverick | ignored | end of life |
natty | ignored | end of life |
oneiric | ignored | end of life |
precise | ignored | end of life |
precise/esm | DNE | precise was needed |
Показывать по
EPSS
2.1 Low
CVSS2
Связанные уязвимости
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2. ...
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.
EPSS
2.1 Low
CVSS2