CVE-2024-45691
20.11.2024, 11:15
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 4.1.13 |
moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.10 |
moodle | moodle | 4.3.0 ≤ 𝑥 < 4.3.7 |
moodle | moodle | 4.4.0 ≤ 𝑥 < 4.4.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases