CVE-2012-0800
low
CVSS v3
—
CVSS v2
2.1
VIR risk
2.1
Description
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://moodle.org/mod/forum/discuss.php?d=194019
References
- http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=6e9989dbd3f261b2e1586ff77b0bf22fc7091485
- http://moodle.org/mod/forum/discuss.php?d=194019
- https://bugzilla.redhat.com/show_bug.cgi?id=783532
- http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=6e9989dbd3f261b2e1586ff77b0bf22fc7091485
- http://moodle.org/mod/forum/discuss.php?d=194019
- https://bugzilla.redhat.com/show_bug.cgi?id=783532
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.