Permissions, Privileges, and Access Controls in Moodle - CVE-2020-25701
Published: November 16, 2020
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists in the tool_uploadcourse function. If the upload course tool was used to delete an enrolment method which did not exist or was not already enabled, the tool would erroneously enable that enrolment method. This could lead to unintended users gaining access to the course.
Affected software
Fedora
moodle
How to mitigate CVE-2020-25701
moodle - addressed in versions 3.8.6-1.fc32, 3.9.3-1.fc33