CVE-2020-14321

HIGH

Moodle Teacher Enrollment Privilege Escalation to RCE

Title source: metasploit

Description

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

Exploits (4)

nomisec WORKING POC 44 stars
by HoangKien1020 · poc
https://github.com/HoangKien1020/CVE-2020-14321
nomisec WORKING POC 20 stars
by lanzt · poc
https://github.com/lanzt/CVE-2020-14321
nomisec WORKING POC 2 stars
by f0ns1 · poc
https://github.com/f0ns1/CVE-2020-14321-modified-exploit
metasploit WORKING POC GOOD
by HoangKien1020, lanz, h00die · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/moodle_teacher_enrollment_priv_esc_to_rce.rb

Scores

CVSS v3 8.8
EPSS 0.3940
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (3)
moodle/moodle 3.9.0
moodle/moodle 3.5.0 - 3.5.13
moodle/moodle 3.9.0-beta - 3.9.1Packagist
Published Aug 16, 2022
Tracked Since Feb 18, 2026