Description
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-1233)
WordPress Plugin CP Contact Form with PayPal Cross-Site Scripting (1.2.98)
Java Unspesificed Vulnerability (CVE-2019-2684)
WordPress Plugin GA Universal Cross-Site Request Forgery (1.0)
Squid Resource Management Errors Vulnerability (CVE-2011-4096)