CVE-2020-14321
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
- Moodle
- < 3.5.13, 3.7.7, 3.8.4, 3.9.0
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 16.2% (97th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2022-08-16
CVE-2020-14321 at NVD
11 known exploits for CVE-2020-14321
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2020-14321-modified-exploit
CVE-2020-14321
CVE-2020-14321
Moodle Teacher Enrollment Privilege Escalation / Remote Code Execution Exploit
Moodle Teacher Enrollment Privilege Escalation / Remote Code Execution
Moodle 3.9 - Remote Code Execution (Authenticated) Exploit
Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)
Moodle 3.9 Remote Code Execution
Exploit for Incorrect Authorization in Moodle
Exploit for Incorrect Authorization in Moodle
Moodle Teacher Enrollment Privilege Escalation to RCE