CVE-2020-25699
published 2020-11-19CVE-2020-25699: In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.59%
72.9th percentile
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | >= 3.5 < 3.5.15 | 3.5.15 |
| moodle | moodle | 3.5.0 – 3.5.14 | — |
| moodle | moodle | >= 3.7.0 < 3.7.9 | 3.7.9 |
| moodle | moodle | 3.7.0 – 3.7.8 | — |
| moodle | moodle | >= 3.8.0 < 3.8.6 | 3.8.6 |
| moodle | moodle | 3.8.0 – 3.8.5 | — |
| moodle | moodle | >= 3.9.0 < 3.9.3 | 3.9.3 |
| moodle | moodle | 3.9.0 – 3.9.2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Privilage Escalation in moodle
ghsa·2021-03-29
CVE-2020-25699 [HIGH] CWE-269 Privilage Escalation in moodle
Privilage Escalation in moodle
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
OSV
Privilage Escalation in moodle
osv·2021-03-29
CVE-2020-25699 [HIGH] Privilage Escalation in moodle
Privilage Escalation in moodle
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
OSV
CVE-2020-25699: In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that c
osv·2020-11-19·CVSS 7.5
CVE-2020-25699 [HIGH] CVE-2020-25699: In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that c
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1895425https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6/https://moodle.org/mod/forum/discuss.php?d=413936https://bugzilla.redhat.com/show_bug.cgi?id=1895425https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6/https://moodle.org/mod/forum/discuss.php?d=413936
2020-11-19
Published