cbcvebase.
CVE-2022-30600
published 2022-05-18

CVE-2022-30600: A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.99%
91.3th percentile
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

Affected

13 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
moodlemoodle
moodlemoodle
moodlemoodle>= 3.10 < 3.10.113.10.11
moodlemoodle>= 3.10 < 3.10.113.10.11
moodlemoodle>= 3.11 < 3.11.73.11.7
moodlemoodle>= 3.11 < 3.11.73.11.7
moodlemoodle>= 3.9 < 3.9.143.9.14
moodlemoodle>= 3.9 < 3.9.143.9.14
moodlemoodle>= 4.0 < 4.0.14.0.1
redhatenterprise_linux

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.