Security Advisory

CVE-2020-25699

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-11-19 00:00:00
Last updated 2024-08-04 15:40:36
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.