8.8

CVE-2020-14321

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 3.5.0 < 3.5.13
Moodle ≫ Moodle Version >= 3.7.0 < 3.7.7
Moodle ≫ Moodle Version >= 3.8.0 < 3.8.4
Moodle ≫ Moodle Version 3.9.0 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.24% 0.967
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://moodle.org/mod/forum/discuss.php?d=407393
Patch
Vendor Advisory