lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://moodle.org/mod/forum/discuss.php?d=252414 | patch vendor advisory |
http://openwall.com/lists/oss-security/2014/01/20/1 | mailing list |
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36721 | patch |
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/127533.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/127510.html | vendor advisory |
http://www.securitytracker.com/id/1029647 | vdb entry |