9.8
CVSSv3

CVE-2022-30600

Published: 18/05/2022 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle

moodle moodle 4.0.0

redhat enterprise linux 8.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

Github Repositories

A proof of concept for CVE-2022-30600

Proof of concept for CVE-2022-30600 Overview This repository contains 2 implementations for a proof of concept which exploits CVE-2022-30600 CVE-2022-30600 is a security vulnerability which allows an attacker to bypass the account lockout threshold within the moodle webapp As outlined by the following entry in NVD database nvdnistgov/vuln/detail/CVE-2022-30600, the