Back

HIGH

Moodle: password brute force risk when mobile/web services enabled

Published Oct 23, 2025

Description

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner fedora
Published Oct 23, 2025
Updated Oct 23, 2025
Reserved Oct 13, 2025

CISA Vulnrichment

Updated Oct 23, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner fedora
Published Oct 23, 2025
Updated Oct 23, 2025