#VU48447 Permissions, Privileges, and Access Controls in Moodle - CVE-2020-25701
Published: November 16, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists in the tool_uploadcourse function. If the upload course tool was used to delete an enrolment method which did not exist or was not already enabled, the tool would erroneously enable that enrolment method. This could lead to unintended users gaining access to the course.