Permissions, Privileges, and Access Controls in Moodle - CVE-2020-25698
Published: November 16, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to application does not properly impose security restrictions on enrollment capabilities, when users were restored into an existing course. A remote user with teacher role without permission using course restore can unenroll students.