PT-2025-43447 · Moodle · Moodle

Published

2025-10-23

·

Updated

2025-11-17

·

CVE-2025-62399

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description The authentication endpoints for Moodle’s mobile and web services did not adequately limit repeated password attempts, leaving them open to brute-force attacks. The vulnerable endpoints are the mobile and web service authentication endpoints. The issue involves insufficient restriction of password attempts, potentially allowing attackers to guess valid credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BIT-MOODLE-2025-62399
CVE-2025-62399
GHSA-M58F-9PVV-8MP2

Affected Products

Moodle