login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-2418 | login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account. |
![]() |
GHSA-4ppg-2mx6-fqx9 | Moodle allows attackers to bypass intended login restrictions |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T05:39:31.951Z
Reserved: 2015-04-10T00:00:00
Link: CVE-2015-3179

No data.

Status : Deferred
Published: 2015-06-01T19:59:22.087
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-3179

No data.

No data.