Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
5.0.0 (semver) before 5.0.3
affected
4.5.0 (semver) before 4.5.7
affected
4.4.0 (semver) before 4.4.11
affected
4.1.0 (semver) before 4.1.21
affected
Description
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
Problem types
Improper Restriction of Excessive Authentication Attempts
Product status
5.0.0 (semver) before 5.0.3
4.5.0 (semver) before 4.5.7
4.4.0 (semver) before 4.4.11
4.1.0 (semver) before 4.1.21
Timeline
| 2025-10-16: | Reported to Red Hat. |
| 2025-10-14: | Made public. |
Credits
Red Hat would like to thank Petr Skoda for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-62399
bugzilla.redhat.com/show_bug.cgi?id=2404432 (RHBZ#2404432)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.