CVE-2020-25701: Medium severity moodle vulnerability

Published Nov 6, 2020
·
Updated

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

Other sources

If the upload course tool was used to delete an enrolment method which did not exist or was not already enabled, the tool would erroneously enable that enrolment method. This could lead to unintended users gaining access to the course.

Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions

Red Hat

Affected Software

15 affected componentsFixes available
composer/moodle/moodle>=3.5<3.5.15
3.5.15
composer/moodle/moodle>=3.7.0<3.7.9
3.7.9
composer/moodle/moodle>=3.8.0<3.8.6
3.8.6
composer/moodle/moodle>=3.9.0<3.9.3
3.9.3
redhat/moodle<3.9.3
3.9.3
redhat/moodle<3.8.6
3.8.6
redhat/moodle<3.7.9
3.7.9
redhat/moodle<3.5.15
3.5.15
redhat/moodle<3.10
3.10
Moodle moodle>=3.5.0<=3.5.14
Moodle moodle>=3.7.0<=3.7.8
Moodle moodle>=3.8.0<=3.8.5
Moodle moodle>=3.9.0<=3.9.2
Fedoraproject Fedora=32
Fedoraproject Fedora=33

Event History

Nov 19, 2020
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionWeakness
Mar 29, 2021
Advisory Published
08:42 PM

Frequently Asked Questions

1

What is the severity of CVE-2020-25701?

The severity of CVE-2020-25701 is considered moderate due to the potential for unauthorized access to courses.

2

How do I fix CVE-2020-25701?

To fix CVE-2020-25701, upgrade Moodle to version 3.5.15, 3.7.9, 3.8.6, or 3.9.3 or later.

3

Which Moodle versions are affected by CVE-2020-25701?

Moodle versions affected by CVE-2020-25701 include 3.9 to 3.9.2, 3.8 to 3.8.5, and 3.7 to 3.7.6.

4

What kind of exploit does CVE-2020-25701 represent?

CVE-2020-25701 represents a vulnerability that could allow unintended users access to courses via erroneous enrollment method enabling.

5

Is there a workaround for CVE-2020-25701?

There is no documented workaround for CVE-2020-25701; the recommended action is to apply the appropriate software update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203