Description
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-1689 Vulnerability (CVE-2012-1689)
WordPress Plugin Cool Timeline (Horizontal & Vertical Timeline) Cross-Site Request Forgery (2.0.2)
Apache Tomcat Other Vulnerability (CVE-2002-2009)
MySQL CVE-2018-2805 Vulnerability (CVE-2018-2805)
Django Improper Input Validation Vulnerability (CVE-2011-4138)