7.5

CVE-2009-4304

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

Data is provided by the National Vulnerability Database (NVD)
MoodleMoodle Version1.8.1
MoodleMoodle Version1.8.2
MoodleMoodle Version1.8.3
MoodleMoodle Version1.8.4
MoodleMoodle Version1.8.5
MoodleMoodle Version1.8.7
MoodleMoodle Version1.8.8
MoodleMoodle Version1.8.9
MoodleMoodle Version1.8.10
MoodleMoodle Version1.9.1
MoodleMoodle Version1.9.2
MoodleMoodle Version1.9.3
MoodleMoodle Version1.9.4
MoodleMoodle Version1.9.5
MoodleMoodle Version1.9.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.25% 0.774
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P