CVE-2020-25700: SQL Injection
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25700?
The severity of CVE-2020-25700 is considered medium, as it allows unauthorized entry manipulation within groups.
How do I fix CVE-2020-25700?
To fix CVE-2020-25700, upgrade Moodle to versions 3.5.15, 3.7.9, 3.8.6, or 3.9.3 or later.
Which versions are affected by CVE-2020-25700?
CVE-2020-25700 affects Moodle versions 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, and 3.5 to 3.5.14.
Is CVE-2020-25700 fixed in the latest Moodle version?
Yes, CVE-2020-25700 is fixed in Moodle version 3.10 and subsequent releases.
What type of vulnerability is CVE-2020-25700?
CVE-2020-25700 is a permissions vulnerability that allows unauthorized access to add entries in groups.