Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
- >= 5.0, <= 5.0.2
- >= 4.5, <= 4.5.6
- >= 4.4, <= 4.4.10
- >= 4.1, <= 4.1.20
A vulnerability exists in Moodle's mobile and web service authentication endpoints, which fail to adequately limit repeated password attempts. This oversight creates a risk of brute-force attacks, allowing attackers to systematically guess passwords for known usernames. The vulnerability affects Moodle versions 5.0 prior to 5.0.3, 4.5 prior to 4.5.7, 4.4 prior to 4.4.11, 4.1 prior to 4.1.21, and earlier unsupported versions.
Exploitation of this vulnerability could lead to unauthorized access to user accounts through successful password guessing via brute-force methods.
Users can upgrade to Moodle versions 5.0.3, 4.5.7, 4.4.11, or 4.1.21 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.