Boletines de Vulnerabilidades

MSA-20-0017: Privilege escalation within a course when restoring role overrides


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. Insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course.Severity/Risk:MinorVersions affected:3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versionsVersions fixed:3.10, 3.9.3, 3.8.6, 3.7.9 and 3.5.15Reported by:Matt PetroCVE identifier:CVE-2020-25699Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=413936&parent=1668771

Identificadores estándar

Propiedad Valor
CVE CVE-2020-25699.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2020-11-17
Ministerio de Defensa
CNI
CCN
CCN-CERT