CVE-2014-0008: Moodle

Medium severity, CVSS 4.0. EPSS: 1.8% chance of exploitation in the next 30 days.

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.

Affected products

  • Moodle Moodle: version 2.5.0 only; version 2.5.1 only; version 2.5.2 only; version 2.5.3 only; version 2.6.0 only; version 2.4.0 only; …

Published 2014-01-20. Last modified 2026-06-17.