lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2014-01-20 07:14
Updated : 2020-12-01 06:52
NVD link : CVE-2014-0008
Mitre link : CVE-2014-0008
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
moodle
- moodle