Описание
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
Ссылки
- Third Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.1.0 (включая) до 4.1.21 (исключая)Версия от 4.4.0 (включая) до 4.4.11 (исключая)Версия от 4.5.0 (включая) до 4.5.7 (исключая)Версия от 5.0.0 (включая) до 5.0.3 (исключая)
Одно из
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.0038
Низкий
7.5 High
CVSS3
Дефекты
CWE-307
Связанные уязвимости
CVSS3: 7.5
ubuntu
11 месяцев назад
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
CVSS3: 7.5
debian
11 месяцев назад
Moodle\u2019s mobile and web service authentication endpoints did not ...
CVSS3: 7.5
github
11 месяцев назад
Moodle vulnerable to brute-force password guesses
EPSS
Процентиль: 31%
0.0038
Низкий
7.5 High
CVSS3
Дефекты
CWE-307