Improper access control in Moodle - CVE-2020-25700

 

Improper access control in Moodle - CVE-2020-25700

Published: November 16, 2020


Vulnerability identifier: #VU48448
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25700
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to some database module web services allowed students to add entries within groups they did not belong to. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2020-25700

Install updates from vendor's website.

Moodle - addressed in versions 3.5.15, 3.7.9, 3.8.6, 3.9.3
moodle - addressed in versions 3.8.6-1.fc32, 3.9.3-1.fc33

External References

Related Security Bulletins