A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| moodle/moodle(Packagist) | 0 | 4.1.13 | N/A |
| moodle/moodle(Packagist) | 4.2.0-beta | 4.2.10 | N/A |
| moodle/moodle(Packagist) | 4.3.0-beta | 4.3.7 | N/A |
| moodle/moodle(Packagist) | 4.4.0-beta | 4.4.3 | N/A |
CVSS Metrics