CVE-2022-30600
CRITICALMoodle - Privilege Escalation
Title source: llmDescription
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0685
EPSS Percentile
91.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-682
Status
published
Affected Products (7)
moodle/moodle
< 3.9.14
moodle/moodle
redhat/enterprise_linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
moodle/moodle
< 4.0.1Packagist
Timeline
Published
May 18, 2022
Tracked Since
Feb 18, 2026