← Back

CVE-2020-25698

nvd nist
Published: Nov 19, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

Affected (6)

1 product
Moodle
1 product
Fedora
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.5.0 to 3.5.14
From 3.7.0 to 3.7.8
From 3.8.0 to 3.8.5
From 3.9.0 to 3.9.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33

Timeline

No history available yet.