Authentication bypass using an alternate path or channel in Moodle - CVE-2021-20282

 

Authentication bypass using an alternate path or channel in Moodle - CVE-2021-20282

Published: March 15, 2021


Vulnerability identifier: #VU51479
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20282
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error that allowed newly created users to bypass email verification process without having an access to the verification email link/secret. A remote attacker can register an account with an email address of other users and gain unauthorized access to the application.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2021-20282

Install updates from vendor's website.

Moodle - addressed in versions 3.5.17, 3.8.8, 3.9.5, 3.10.2
moodle - addressed in versions 3.8.8-1.fc32, 3.9.5-1.fc33, 3.10.2-1.fc34

External References

Related Security Bulletins