CVE-2021-20283: Medium severity moodle vulnerability
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Other sources
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course.
References:
https://moodle.org/mod/forum/discuss.php?d=419654
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20283?
CVE-2021-20283 has been classified as a medium severity vulnerability.
How do I fix CVE-2021-20283?
To fix CVE-2021-20283, upgrade your Moodle installation to versions 3.5.17, 3.8.8, 3.9.5, or 3.10.2.
Which versions of Moodle are affected by CVE-2021-20283?
CVE-2021-20283 affects Moodle versions prior to 3.10.2, 3.9.5, 3.8.8, and 3.5.17.
Is CVE-2021-20283 a remote code execution vulnerability?
No, CVE-2021-20283 is not a remote code execution vulnerability; it relates to improper permission validation.
What types of attacks could exploit CVE-2021-20283?
CVE-2021-20283 could enable unauthorized users to view other users' enrolled courses.