Описание
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
3.5 Low
CVSS2
Дефекты
Связанные уязвимости
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x ...
Moodle allows attackers to bypass intended login restrictions
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю обойти ограничения входа в систему
EPSS
3.5 Low
CVSS2