CVE Vulnerabilities

CVE-2009-4304

Published: Dec 16, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle1.8.1 (including)1.8.1 (including)
MoodleMoodle1.8.2 (including)1.8.2 (including)
MoodleMoodle1.8.3 (including)1.8.3 (including)
MoodleMoodle1.8.4 (including)1.8.4 (including)
MoodleMoodle1.8.5 (including)1.8.5 (including)
MoodleMoodle1.8.7 (including)1.8.7 (including)
MoodleMoodle1.8.8 (including)1.8.8 (including)
MoodleMoodle1.8.9 (including)1.8.9 (including)
MoodleMoodle1.8.10 (including)1.8.10 (including)
MoodleMoodle1.9.1 (including)1.9.1 (including)
MoodleMoodle1.9.2 (including)1.9.2 (including)
MoodleMoodle1.9.3 (including)1.9.3 (including)
MoodleMoodle1.9.4 (including)1.9.4 (including)
MoodleMoodle1.9.5 (including)1.9.5 (including)
MoodleMoodle1.9.6 (including)1.9.6 (including)
MoodleUbuntudapper*
MoodleUbuntuhardy*
MoodleUbuntuintrepid*
MoodleUbuntujaunty*
MoodleUbuntukarmic*
MoodleUbuntulucid*
MoodleUbuntumaverick*

References