A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
{
"cpes": [
"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"cpe:2.3:a:moodle:moodle:4.0.0:-:*:*:*:*:*:*"
],
"severity": "Critical"
}