Permissions, Privileges, and Access Controls in Moodle - CVE-2020-25698
Published: November 16, 2020
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to application does not properly impose security restrictions on enrollment capabilities, when users were restored into an existing course. A remote user with teacher role without permission using course restore can unenroll students.
Affected software
Fedora
moodle
How to mitigate CVE-2020-25698
moodle - addressed in versions 3.8.6-1.fc32, 3.9.3-1.fc33