Lucene search

K
osvGoogleOSV:GHSA-2PHX-W35G-X9VM
HistoryMay 13, 2022 - 1:12 a.m.

Moodle Weak Password Recovery Mechanism for Forgotten Password

2022-05-1301:12:40
Google
osv.dev
4
moodle
password recovery
web service tokens
security
software

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

36.5%

In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

36.5%