HIGH
Moodle: password brute force risk when mobile/web services enabled
Published Oct 23, 2025
7.5
HIGHCVSS 3.1
EPSS 0.40%
Description
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2025-62399 vdb-entryx_refsource_REDHATThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2404432 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-35668 Advisory
- https://github.com/advisories/GHSA-m58f-9pvv-8mp2 Advisory
- https://github.com/moodle/moodle/commit/e4d02567c922c537086de9f59f063ca073552a3a
- https://moodle.org/mod/forum/discuss.php?d=470388
- https://nvd.nist.gov/vuln/detail/CVE-2025-62399
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-62399 | vdb-entryx_refsource_REDHATThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2404432 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-35668 | Advisory | |
| https://github.com/advisories/GHSA-m58f-9pvv-8mp2 | Advisory | |
| https://github.com/moodle/moodle/commit/e4d02567c922c537086de9f59f063ca073552a3a | ||
| https://moodle.org/mod/forum/discuss.php?d=470388 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-62399 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Oct 23, 2025
Updated Oct 23, 2025
Reserved Oct 13, 2025
Link CVE-2025-62399
CISA Vulnrichment
Updated Oct 23, 2025
Red Hat
No data
GitHub
Link GHSA-M58F-9PVV-8MP2