It was possible to bypass the login notification mechanism, so a user would not be notified if their account received a new login. This could make it easier for unauthorised users to log in without detection. Note: Valid login credentials (such as username and password) were still required.
| Severity/Risk: | Minor |
| Versions affected: | 5.2 to 5.2.2, 5.1 to 5.1.6, 5.0 to 5.0.9, 4.5 to 4.5.13 and earlier unsupported versions |
| Versions fixed: | 5.2.3, 5.1.7, 5.0.10 and 4.5.14 |
| Reported by: | Brendan Heywood |
| CVE identifier: | Pending |
| Changes (main): | http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-87817 |
| Tracker issue: | MDL-87817 Possible to bypass the login notification mechanism |