MEDIUM
The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network
Published Jul 21, 2012
5.0
MEDIUMCVSS 2.0
EPSS 1.31%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.