Medium severity5.3NVD Advisory· Published Nov 19, 2020· Updated Jun 17, 2026
CVE-2020-25701
CVE-2020-25701
Description
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 3.9.0, < 3.9.3 | 3.9.3 |
moodle/moodlePackagist | >= 3.8.0, < 3.8.6 | 3.8.6 |
moodle/moodlePackagist | >= 3.7.0, < 3.7.9 | 3.7.9 |
moodle/moodlePackagist | >= 3.5, < 3.5.15 | 3.5.15 |
Affected products
6cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- Moodle/Moodledescription
- osv-coords2 versions
>= 3.5.0, < 3.5.15+ 1 more
- (no CPE)range: >= 3.5.0, < 3.5.15
- (no CPE)range: >= 3.9.0, < 3.9.3
Patches
Vulnerability mechanics
References
9- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-c9hq-g4q8-w893ghsaADVISORY
- moodle.org/mod/forum/discuss.phpnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-25701ghsaADVISORY
- github.com/moodle/moodle/commit/b8e1eec4c77c858de87fedf4e405e929539ea0c5ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GUghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GU/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6/nvd
News mentions
0No linked articles in our index yet.