CVE Vulnerabilities

CVE-2020-25698

Published: Nov 19, 2020 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Users enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 3.5.0 (including) 3.5.14 (including)
Moodle Moodle 3.7.0 (including) 3.7.8 (including)
Moodle Moodle 3.8.0 (including) 3.8.5 (including)
Moodle Moodle 3.9.0 (including) 3.9.2 (including)

References