Permissions, Privileges, and Access Controls in Moodle - CVE-2020-14321
Published: July 20, 2020 / Updated: November 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions within ourse enrolments. A remote authenticated attacker with teacher permission can escalate privileges from teacher role into manager role.
Affected software
How to mitigate CVE-2020-14321
Links to Public Exploits and PoC-codes
- Exploit #7068 - Moodle 3.9 - Remote Code Execution (RCE) (Authenticated) (November 25, 2021)
- Exploit #6870 - Moodle Teacher Enrollment Privilege Escalation to RCE (October 12, 2021)
- Exploit #5517 - Moodle_3.9_RCE_AutoPwn (AutoPwn Script for Moodle 3.9 leveraging CVE-2020–20282, CVE-2020–14320,CVE-2020–14321) (June 1, 2021)
- Exploit #5329 - CVE-2020-14321 (Python script to exploit CVE-2020-14321 - Moodle 3.9 - Course enrollments allowed privilege escalation from teacher role into manager role to RCE.) (April 30, 2021)
- Exploit #3608 - CVE-2020-14321 (Course enrolments allowed privilege escalation from teacher role into manager role to RCE) (July 28, 2020)