Moodle Authentication Endpoints Brute-Force Vulnerability

Vulnerability

A vulnerability exists in Moodle's mobile and web service authentication endpoints, which fail to adequately limit repeated password attempts. This oversight creates a risk of brute-force attacks, allowing attackers to systematically guess passwords for known usernames. The vulnerability affects Moodle versions 5.0 prior to 5.0.3, 4.5 prior to 4.5.7, 4.4 prior to 4.4.11, 4.1 prior to 4.1.21, and earlier unsupported versions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to user accounts through successful password guessing via brute-force methods.

Remediation

Users can upgrade to Moodle versions 5.0.3, 4.5.7, 4.4.11, or 4.1.21 to address this vulnerability.

Added: Oct 23, 2025, 12:18 PM
Updated: Oct 23, 2025, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
8.7
remediation
7.7
relevance
0.8
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.