PT-2010-3283 · Moodle · Moodle
Published
2010-04-29
·
Updated
2022-05-13
·
CVE-2010-1613
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moodle versions 1.8.x through 1.9.7
Description
The issue makes it easier for remote attackers to conduct session fixation attacks because a specific security setting is not enabled by default.
Recommendations
For Moodle versions 1.8.x through 1.9.7, enable the "Regenerate session id during login" setting to mitigate the risk of session fixation attacks.
Fix
Session Fixation
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moodle