Lucene search

K
cveRedhatCVE-2014-0008
HistoryJan 20, 2014 - 3:14 p.m.

CVE-2014-0008

2014-01-2015:14:25
CWE-255
redhat
web.nvd.nist.gov
28
moodle
adminlib.php
cleartext passwords
sensitive information
nvd
cve-2014-0008

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0.002

Percentile

60.9%

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.

Affected configurations

Nvd
Node
moodlemoodleMatch2.5.0
OR
moodlemoodleMatch2.5.1
OR
moodlemoodleMatch2.5.2
OR
moodlemoodleMatch2.5.3
Node
moodlemoodleMatch2.6.0
Node
moodlemoodleMatch2.4.0
OR
moodlemoodleMatch2.4.1
OR
moodlemoodleMatch2.4.2
OR
moodlemoodleMatch2.4.3
OR
moodlemoodleMatch2.4.4
OR
moodlemoodleMatch2.4.5
OR
moodlemoodleMatch2.4.6
OR
moodlemoodleMatch2.4.7
Node
moodlemoodleRange2.3.11
OR
moodlemoodleMatch2.3.0
OR
moodlemoodleMatch2.3.1
OR
moodlemoodleMatch2.3.2
OR
moodlemoodleMatch2.3.3
OR
moodlemoodleMatch2.3.4
OR
moodlemoodleMatch2.3.5
OR
moodlemoodleMatch2.3.6
OR
moodlemoodleMatch2.3.7
OR
moodlemoodleMatch2.3.8
OR
moodlemoodleMatch2.3.9
OR
moodlemoodleMatch2.3.10
VendorProductVersionCPE
moodlemoodle2.5.0cpe:2.3:a:moodle:moodle:2.5.0:*:*:*:*:*:*:*
moodlemoodle2.5.1cpe:2.3:a:moodle:moodle:2.5.1:*:*:*:*:*:*:*
moodlemoodle2.5.2cpe:2.3:a:moodle:moodle:2.5.2:*:*:*:*:*:*:*
moodlemoodle2.5.3cpe:2.3:a:moodle:moodle:2.5.3:*:*:*:*:*:*:*
moodlemoodle2.6.0cpe:2.3:a:moodle:moodle:2.6.0:*:*:*:*:*:*:*
moodlemoodle2.4.0cpe:2.3:a:moodle:moodle:2.4.0:*:*:*:*:*:*:*
moodlemoodle2.4.1cpe:2.3:a:moodle:moodle:2.4.1:*:*:*:*:*:*:*
moodlemoodle2.4.2cpe:2.3:a:moodle:moodle:2.4.2:*:*:*:*:*:*:*
moodlemoodle2.4.3cpe:2.3:a:moodle:moodle:2.4.3:*:*:*:*:*:*:*
moodlemoodle2.4.4cpe:2.3:a:moodle:moodle:2.4.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 251

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0.002

Percentile

60.9%