PT-2020-16163 · Moodle+1 · Moodle+1

Víctor Déniz Falcón

·

Published

2020-11-08

·

Updated

2024-03-06

·

CVE-2020-25701

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 3.5 to 3.5.14 Moodle versions 3.7 to 3.7.8 Moodle versions 3.8 to 3.8.5 Moodle versions 3.9 to 3.9.2
Description The upload course tool in Moodle contains an issue where deleting a non-existent or disabled enrollment method would incorrectly enable it, potentially allowing unintended users to access the course.
Recommendations For Moodle versions 3.5 to 3.5.14, update to version 3.5.15 or later. For Moodle versions 3.7 to 3.7.8, update to version 3.7.9 or later. For Moodle versions 3.8 to 3.8.5, update to version 3.8.6 or later. For Moodle versions 3.9 to 3.9.2, update to version 3.9.3 or later.

Fix

Incorrect Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3235
ALT-PU-2020-3289
ALT-PU-2022-1641
BIT-MOODLE-2020-25701
CVE-2020-25701
GHSA-C9HQ-G4Q8-W893

Affected Products

Alt Linux
Moodle