Executive brief
Moodle, a widely used learning management system, contains a security flaw where web service access tokens remain active even after a user changes their password. This means that if an unauthorized person or device has obtained a token, they can continue to access the user's account and data even after the user attempts to secure the account by updating their credentials. This could lead to persistent unauthorized access to student or teacher information.
Technical details
A session management vulnerability exists in Moodle versions 2.x and 3.x where the application fails to revoke or invalidate active web service tokens during a password change event. This includes both user-initiated password changes and administrative forced password resets. An attacker who has previously compromised a web service token can maintain persistent access to the API and user data regardless of credential updates. The vulnerability is categorized under CWE-640 (Weak Password Recovery Mechanism) and allows for continued unauthorized interaction with the platform's web services. Patches have been released by the vendor to address this behavior.
Affected products
- Moodle Moodle 2.x, 3.x
Timeline
- 2016-09-26: advisory: Initial vendor advisory and security focus BID published
- 2017-01-20: disclosed: NVD publication date