CVE Vulnerabilities

CVE-2025-62399

Improper Restriction of Excessive Authentication Attempts

Published: Oct 23, 2025 | Modified: Nov 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

Weakness

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle4.1.0 (including)4.1.21 (excluding)
MoodleMoodle4.4.0 (including)4.4.11 (excluding)
MoodleMoodle4.5.0 (including)4.5.7 (excluding)
MoodleMoodle5.0.0 (including)5.0.3 (excluding)

Potential Mitigations

  • Common protection mechanisms include:

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].

  • Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]

References