CVE-2020-25701
Summary
| CVE | CVE-2020-25701 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-19 17:15:00 UTC |
| Updated | 2023-11-07 03:20:00 UTC |
| Description | If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1895432 – (CVE-2020-25701) CVE-2020-25701 moodle: tool_uploadcourse creates new enrol instances unexpectedly in some circumstances | MISC | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| Moodle.org: MSA-20-0019: tool_uploadcourse creates new enrol instances unexpectedly in some circumstances | MISC | moodle.org | Vendor Advisory |
| [SECURITY] Fedora 32 Update: moodle-3.8.6-1.fc32 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 33 Update: moodle-3.9.3-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 32 Update: moodle-3.8.6-1.fc32 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 33 Update: moodle-3.9.3-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.