A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Moodle | Moodle | 3.9 (including) | 3.9.14 (excluding) |
| Moodle | Moodle | 3.10 (including) | 3.10.11 (excluding) |
| Moodle | Moodle | 3.11 (including) | 3.11.7 (excluding) |
| Moodle | Moodle | 4.0.0 (including) | 4.0.0 (including) |
| Moodle | Ubuntu | bionic | * |