#VU124621 Improper Restriction of Excessive Authentication Attempts in Moodle - CVE-2025-62399
Published: March 26, 2026 / Updated: March 26, 2026
Moodle
moodle.org
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not limit the number of password attempts when the mobile client and auth_webservice were enabled. A remote attacker can brute force password checks against known usernames.