First published: Tue Aug 16 2022(Updated: )
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.5.0<3.5.13 | |
Moodle Moodle | >=3.7.0<3.7.7 | |
Moodle Moodle | >=3.8.0<3.8.4 | |
Moodle Moodle | =3.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14321 is a vulnerability in Moodle, versions before 3.9.1, 3.8.4, 3.7.7, and 3.5.13, that allows teachers to assign themselves the manager role within a course.
The severity of CVE-2020-14321 is high with a score of 8.8.
CVE-2020-14321 affects Moodle versions before 3.9.1, 3.8.4, 3.7.7, and 3.5.13.
Teachers were able to assign themselves the manager role within a course in affected Moodle versions before 3.9.1, 3.8.4, 3.7.7, and 3.5.13.
Yes, upgrading to Moodle versions 3.9.1, 3.8.4, 3.7.7, or 3.5.13 will fix the vulnerability.