Description
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.
Remediation
References
Related Vulnerabilities
ProjectSend Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2023-53905)
WordPress Plugin Zingiri Web Shop 'abspath' Parameter Remote File Include (2.4.6)
Drupal Improper Access Control Vulnerability (CVE-2016-3165)
WordPress Plugin EWWW Image Optimizer Cross-Site Request Forgery (5.8.1)