Vulnerability Name: | CVE-2020-25698 (CCN-192056) | ||||||||||||
Assigned: | 2019-11-16 | ||||||||||||
Published: | 2019-11-16 | ||||||||||||
Updated: | 2020-12-02 | ||||||||||||
Summary: | Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-25698 Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1895419 Source: XF Type: UNKNOWN moodle-cve202025698-sec-bypass(192056) Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2020-db73e37548 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2020-304aa2c365 Source: CCN Type: Moodle Security Advisory MSA-20-0016 Teacher is able to unenrol users without permission using course restore Source: MISC Type: Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=413935 Source: CCN Type: WhiteSource Vulnerability Database CVE-2020-25698 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||
BACK |