← Back

CVE-2020-25701

nvd nist
Published: Nov 19, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

Affected (6)

1 product
Moodle
1 product
Fedora
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.5.0 to 3.5.14
From 3.7.0 to 3.7.8
From 3.8.0 to 3.8.5
From 3.9.0 to 3.9.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33

Timeline

No history available yet.