Description
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0685
EPSS Percentile
91.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-682
Status
published
Products (7)
fedoraproject/fedora
34
fedoraproject/fedora
35
fedoraproject/fedora
36
moodle/moodle
4.0.0
moodle/moodle
3.9 - 3.9.14
moodle/moodle
4.0 - 4.0.1Packagist
redhat/enterprise_linux
8.0
Published
May 18, 2022
Tracked Since
Feb 18, 2026