Описание
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.22 (исключая)Версия от 4.4.0 (включая) до 4.4.11 (исключая)Версия от 4.5.0 (включая) до 4.5.8 (исключая)Версия от 5.0.0 (включая) до 5.0.4 (исключая)
Одно из
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:5.1.0:-:*:*:*:*:*:*
EPSS
Процентиль: 6%
0.00022
Низкий
7.5 High
CVSS3
Дефекты
CWE-307
Связанные уязвимости
CVSS3: 7.5
ubuntu
2 месяца назад
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.
CVSS3: 7.5
debian
2 месяца назад
A flaw was found in Moodle. A remote attacker could exploit a lack of ...
CVSS3: 7.5
github
2 месяца назад
Moodle Affected by Improper Restriction of Excessive Authentication Attempts
EPSS
Процентиль: 6%
0.00022
Низкий
7.5 High
CVSS3
Дефекты
CWE-307