← Back

CVE-2009-4302

nvd nist
Published: Dec 16, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

Affected (15)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
Version 1.8.10
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.5
Version 1.8.7
Version 1.8.8
Version 1.8.9
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4
Version 1.9.5
Version 1.9.6

Related CWEs

References (18)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.