CVE-2011-4590
Moodle - Authentication Bypass
Title source: ruleDescription
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
Scores
EPSS
0.0014
EPSS Percentile
33.7%
Classification
CWE
CWE-287
Status
draft
Affected Products (9)
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
Timeline
Published
Jul 20, 2012
Tracked Since
Feb 18, 2026