HIGH
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course
Published Nov 19, 2020
7.5
HIGHCVSS 3.1
EPSS 1.92%
Description
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
Affected products
- Vendor n/a Product Moodle Defaultunknown
Affected
- Fixed in 3.10
- Fixed in 3.5.15
- Fixed in 3.7.9
- Fixed in 3.8.6
- Fixed in 3.9.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Moodle | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- https://bugzilla.redhat.com/show_bug.cgi?id=1895419 x_refsource_MISCIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-0714 Advisory
- https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-67837
- https://github.com/advisories/GHSA-vxhx-gmhm-623c Advisory
- https://github.com/moodle/moodle/commit/c8ac07fb50fa92eee1d574823fbda09e1b309a63
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GU/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6/
- https://moodle.org/mod/forum/discuss.php?d=413935 x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25698
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 19, 2020
Updated Aug 4, 2024
Reserved Sep 16, 2020
Link CVE-2020-25698
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-VXHX-GMHM-623C