Back

HIGH

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course

Published Nov 19, 2020

Description

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Nov 19, 2020
Updated Aug 4, 2024
Reserved Sep 16, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner redhat
Published Nov 19, 2020
Updated Aug 4, 2024