CVE-2014-7845 PUBLISHED CVSS 7.5 HIGH

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

EPSS 0.71% · 72.2th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
0.71%
72.2th percentile

Affected Products

VendorProductVersions
moodlemoodle2.7.0, 2.7.1, 2.7.2
moodlemoodle2.7.0, 2.6.0, 2.5.0
n/an/an/a

Timeline

References

Open in Interactive Console →