CVE-2020-25629
Description
Moodle users with 'Log in as' capability in a course can gain site administration privileges by impersonating a System manager.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Moodle users with 'Log in as' capability in a course can gain site administration privileges by impersonating a System manager.
Vulnerability
Analysis
CVE-2020-25629 is a privilege escalation vulnerability in Moodle, affecting versions 3.5 to 3.5.13, 3.7 to 3.7.7, 3.8 to 3.8.4, and 3.9 to 3.9.1, as well as earlier unsupported releases [1]. The issue lies in the 'Log in as' feature, where a user with the 'moodle/site:viewparticipants' capability in a course context (typically a course manager) can impersonate another user. By logging in as a System manager, the attacker inadvertently inherits site-level administrative capabilities that exceed their intended permissions [1].
Attack
Vector
Exploitation requires an authenticated user who possesses the 'Log in as' capability in at least one course [1]. No special network access is needed beyond normal web application usage. The attacker simply initiates a session as a target user who holds the System manager role [1]. The vulnerability is triggered through the standard impersonation workflow, making it straightforward for a course manager to exploit without requiring additional privileges or external tools.
Impact
Successful exploitation allows a course manager to gain unauthorized access to site administration functions [1]. This includes the ability to modify system-wide settings, manage users across the entire site, and potentially compromise the confidentiality, integrity, and availability of the Moodle installation. The privilege escalation bypasses the intended role hierarchy, where course managers should only have authority within their assigned courses.
Mitigation
Moodle has released fixed versions: 3.9.2, 3.8.5, 3.7.8, and 3.5.14 [1]. Administrators should upgrade immediately to these or later versions. No workaround has been published, making patching the only reliable mitigation. The vulnerability is not known to be exploited in the wild, but given the ease of exploitation, prompt action is recommended.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 3.9, < 3.9.2 | 3.9.2 |
moodle/moodlePackagist | >= 3.8, < 3.8.5 | 3.8.5 |
moodle/moodlePackagist | >= 3.7, < 3.7.8 | 3.7.8 |
moodle/moodlePackagist | >= 3.5, < 3.5.14 | 3.5.14 |
Affected products
3- Moodle/Moodledescription
- osv-coords2 versions
>= 3.5.0, < 3.5.14+ 1 more
- (no CPE)range: >= 3.5.0, < 3.5.14
- (no CPE)range: >= 3.9, < 3.9.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-f5r8-7h4f-jr9xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-25629ghsaADVISORY
- moodle.org/mod/forum/discuss.phpghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.