CVE-2020-14321 describes a critical privilege escalation vulnerability in Moodle versions prior to 3.9.1, 3.8.4, 3.7.7, and 3.5.13, where teachers could illicitly assign themselves the manager role within their courses. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low privileges and no user interaction, leading to complete compromise of confidentiality, integrity, and availability within the affected course. While not currently on CISA's KEV catalog or showing active exploitation in the wild, a Metasploit module exists, demonstrating a clear path to remote code execution, and its high EPSS and FAUCET Risk Scores indicate significant exploitability potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 3.5.13CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.7.0, < 3.7.7CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.8.0, < 3.8.4CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
3.9.0CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:3.9.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.