VYPR
High severityNVD Advisory· Published Dec 8, 2020· Updated Aug 4, 2024

CVE-2020-25629

CVE-2020-25629

Description

Moodle users with 'Log in as' capability in a course can gain site administration privileges by impersonating a System manager.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Moodle users with 'Log in as' capability in a course can gain site administration privileges by impersonating a System manager.

Vulnerability

Analysis

CVE-2020-25629 is a privilege escalation vulnerability in Moodle, affecting versions 3.5 to 3.5.13, 3.7 to 3.7.7, 3.8 to 3.8.4, and 3.9 to 3.9.1, as well as earlier unsupported releases [1]. The issue lies in the 'Log in as' feature, where a user with the 'moodle/site:viewparticipants' capability in a course context (typically a course manager) can impersonate another user. By logging in as a System manager, the attacker inadvertently inherits site-level administrative capabilities that exceed their intended permissions [1].

Attack

Vector

Exploitation requires an authenticated user who possesses the 'Log in as' capability in at least one course [1]. No special network access is needed beyond normal web application usage. The attacker simply initiates a session as a target user who holds the System manager role [1]. The vulnerability is triggered through the standard impersonation workflow, making it straightforward for a course manager to exploit without requiring additional privileges or external tools.

Impact

Successful exploitation allows a course manager to gain unauthorized access to site administration functions [1]. This includes the ability to modify system-wide settings, manage users across the entire site, and potentially compromise the confidentiality, integrity, and availability of the Moodle installation. The privilege escalation bypasses the intended role hierarchy, where course managers should only have authority within their assigned courses.

Mitigation

Moodle has released fixed versions: 3.9.2, 3.8.5, 3.7.8, and 3.5.14 [1]. Administrators should upgrade immediately to these or later versions. No workaround has been published, making patching the only reliable mitigation. The vulnerability is not known to be exploited in the wild, but given the ease of exploitation, prompt action is recommended.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
moodle/moodlePackagist
>= 3.9, < 3.9.23.9.2
moodle/moodlePackagist
>= 3.8, < 3.8.53.8.5
moodle/moodlePackagist
>= 3.7, < 3.7.83.7.8
moodle/moodlePackagist
>= 3.5, < 3.5.143.5.14

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.