A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
]
}