CVE-2020-25698
Last modified
CVE-2020-25698 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. EPSS estimates a 1.90% chance of exploitation in the next 30 days.
Description
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | >= 3.5.0, <= 3.5.14 |
| Moodle | Moodle | >= 3.7.0, <= 3.7.8 |
| Moodle | Moodle | >= 3.8.0, <= 3.8.5 |
| Moodle | Moodle | >= 3.9.0, <= 3.9.2 |
| Fedoraproject | Fedora | 32 |
| Fedoraproject | Fedora | 33 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1895419Issue Tracking, Vendor Advisory
- https://moodle.org/mod/forum/discuss.php?d=413935Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1895419Issue Tracking, Vendor Advisory
- https://moodle.org/mod/forum/discuss.php?d=413935Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25698?
How severe is CVE-2020-25698?
How do I fix CVE-2020-25698?
Are you affected by CVE-2020-25698?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
