Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-25629

Опубликовано: 08 дек. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.5.14 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.7.0 (включая) до 3.7.8 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.8.0 (включая) до 3.8.5 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.9.0 (включая) до 3.9.2 (исключая)

EPSS

Процентиль: 66%
0.00535
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
debian
больше 4 лет назад

A vulnerability was found in Moodle where users with "Log in as" capab ...

CVSS3: 8.8
github
около 3 лет назад

Moodle incorrect access control

EPSS

Процентиль: 66%
0.00535
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-284
CWE-862