CVE-2020-14321: High severity moodle vulnerability
Published Aug 16, 2022
·Updated
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Affected Software
8 affected componentsFixes available
Moodle moodle>=3.5.0<3.5.13
Moodle moodle>=3.7.0<3.7.7
Moodle moodle>=3.8.0<3.8.4
Moodle moodle=3.9.0
composer/moodle/moodle<3.5.13
3.5.13
composer/moodle/moodle>=3.6.0-beta<3.7.7
3.7.7
composer/moodle/moodle>=3.8.0-beta<3.8.4
3.8.4
composer/moodle/moodle>=3.9.0-beta<3.9.1
3.9.1
Remediation
Patch Available
Event History
Aug 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Aug 17, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2020-14321?
CVE-2020-14321 is a vulnerability in Moodle, versions before 3.9.1, 3.8.4, 3.7.7, and 3.5.13, that allows teachers to assign themselves the manager role within a course.
2
What is the severity of CVE-2020-14321?
The severity of CVE-2020-14321 is high with a score of 8.8.
3
How does CVE-2020-14321 affect Moodle?
CVE-2020-14321 affects Moodle versions before 3.9.1, 3.8.4, 3.7.7, and 3.5.13.
4
How can teachers assign themselves the manager role in a Moodle course?
Teachers were able to assign themselves the manager role within a course in affected Moodle versions before 3.9.1, 3.8.4, 3.7.7, and 3.5.13.
5
Is there a fix available for CVE-2020-14321?
Yes, upgrading to Moodle versions 3.9.1, 3.8.4, 3.7.7, or 3.5.13 will fix the vulnerability.