PT-2022-8563 · Moodle+1 · Moodle+1

Kien Hoang

·

Published

2020-10-15

·

Updated

2024-03-06

·

CVE-2020-14321

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 3.9.1 Moodle versions prior to 3.8.4 Moodle versions prior to 3.7.7 Moodle versions prior to 3.5.13
Description The issue allows teachers of a course to assign themselves the manager role within that course.
Recommendations For versions prior to 3.9.1, update to version 3.9.1 or later. For versions prior to 3.8.4, update to version 3.8.4 or later. For versions prior to 3.7.7, update to version 3.7.7 or later. For versions prior to 3.5.13, update to version 3.5.13 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3059
ALT-PU-2020-3235
ALT-PU-2020-3289
ALT-PU-2021-1050
ALT-PU-2021-1098
ALT-PU-2021-1445
ALT-PU-2021-1497
ALT-PU-2021-1777
ALT-PU-2021-2215
ALT-PU-2021-2787
ALT-PU-2021-3258
ALT-PU-2021-3335
ALT-PU-2022-1064
ALT-PU-2022-1476
ALT-PU-2022-1641
ALT-PU-2022-2450
ALT-PU-2023-2012
ALT-PU-2023-2057
ALT-PU-2023-5127
BIT-MOODLE-2020-14321
CVE-2020-14321
GHSA-9Q29-JCJW-FW7H

Affected Products

Alt Linux
Moodle