Description
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0714 | Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10. |
Github GHSA |
GHSA-vxhx-gmhm-623c | Improper Access Control in moodle |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.632Z
Reserved: 2020-09-16T00:00:00.000Z
Link: CVE-2020-25698
No data.
Status : Modified
Published: 2020-11-19T17:15:12.560
Modified: 2026-06-17T03:07:09.030
Link: CVE-2020-25698
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-284
Improper Access Control
- NVD-CWE-noinfo
EUVD
Github GHSA