#VU48448 Improper access control in Moodle - CVE-2020-25700
Published: November 16, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to some database module web services allowed students to add entries within groups they did not belong to. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.