CVE-2012-0794: Moodle

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

Affected products

  • Moodle Moodle: version 1.9.1 only; version 1.9.2 only; version 1.9.3 only; version 1.9.4 only; version 1.9.5 only; version 1.9.6 only; …

Published 2012-07-17. Last modified 2026-06-16.