CVE-2020-25698
Summary
| CVE | CVE-2020-25698 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-19 17:15:00 UTC |
| Updated | 2023-11-07 03:20:00 UTC |
| Description | Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1895419 – (CVE-2020-25698) CVE-2020-25698 moodle: Teacher is able to unenrol users without permission using course restore | MISC | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| Moodle.org: MSA-20-0016: Teacher is able to unenrol users without permission using course restore | MISC | moodle.org | Vendor Advisory |
| [SECURITY] Fedora 32 Update: moodle-3.8.6-1.fc32 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 33 Update: moodle-3.9.3-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 32 Update: moodle-3.8.6-1.fc32 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| [SECURITY] Fedora 33 Update: moodle-3.9.3-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.