moodlesession value security issue

moodlesession value security issue

by Dnyaneshwar K -
Number of replies: 3

Hello Team,

I am login with admin and copy the moodlesession key value from the cookies tab and logged in with the student user using private browser and open the cookies tab from the application in the chrome tab and paste the admin moodlesession value in student cookies and refresh the page then admin gets login there.

I have tried moodle sangbox as well and having same issue there and I think It's a major security issue if someone gets user moodlesession vakue. is there any way to handle this?


Average of ratings: -
In reply to Dnyaneshwar K

Ri: moodlesession value security issue

by Sergio Rabellino -
Picture of Particularly helpful Moodlers Picture of Plugin developers
IMHO , this is not an issue, it's only how every website session management actually works in the world.
Average of ratings: Useful (1)
In reply to Sergio Rabellino

Re: Ri: moodlesession value security issue

by Dnyaneshwar K -
But what about security, using the moodlesession value anyone can log in without a username and password.?
In reply to Dnyaneshwar K

Ri: Re: Ri: moodlesession value security issue

by Sergio Rabellino -
Picture of Particularly helpful Moodlers Picture of Plugin developers
Yes, you are stealing a session identifier, that's why we usually protect the transmission of this information with HTTPS protocol, to avoid that anyone can steal it.
You are attacking your browser, not moodle.
Average of ratings: Useful (3)