Description
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.6.0 Multiple Vulnerabilities (1.6.0)
e107 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-16388)
MySQL Uncontrolled Resource Consumption Vulnerability (CVE-2025-50091)
Drupal Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2017-6381)