CVE-2020-25629: High severity moodle vulnerability
A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25629?
CVE-2020-25629 is classified as a medium to high severity vulnerability due to unauthorized access to site administration capabilities.
How do I fix CVE-2020-25629?
To fix CVE-2020-25629, upgrade to Moodle versions 3.5.14, 3.7.8, 3.8.5, or 3.9.2.
Which Moodle versions are affected by CVE-2020-25629?
CVE-2020-25629 affects Moodle versions 3.5.0 to 3.5.13, 3.7.0 to 3.7.7, 3.8.0 to 3.8.4, and 3.9.0 to 3.9.1.
Who is impacted by CVE-2020-25629?
Users with the 'Log in as' capability in course contexts, typically course managers, are impacted by CVE-2020-25629.
What can attackers do with CVE-2020-25629?
Attackers exploiting CVE-2020-25629 can gain access to certain site administration capabilities by logging in as a System manager.