CVE-2020-25698: High severity Moodle moodle vulnerability
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
Other sources
Users' enrolment capabilities were not being sufficiently checked when they restored into an existing course, could lead to them unenrolling users without having permission to do so.
Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25698?
CVE-2020-25698 has a high severity rating due to the potential for unauthorized user unenrollment.
How do I fix CVE-2020-25698?
To fix CVE-2020-25698, update Moodle to version 3.5.15, 3.7.9, 3.8.6, or 3.9.3 or later.
Which Moodle versions are affected by CVE-2020-25698?
CVE-2020-25698 affects Moodle versions 3.5.0 to 3.5.14, 3.7.0 to 3.7.8, 3.8.0 to 3.8.5, and 3.9.0 to 3.9.2.
Can CVE-2020-25698 be exploited remotely?
Yes, CVE-2020-25698 can be exploited remotely by unauthorized users with limited access levels.
What are the impacts of CVE-2020-25698 on Moodle courses?
CVE-2020-25698 allows users to unenroll other users from courses without having the necessary permissions.