In Moodle before versions 3.9.1, 3.8.4, 3.7.7, and 3.5.13, an authorization flaw allowed a teacher within a course to assign themselves the manager role in that same course. The issue is an incorrect authorization/privilege management weakness in Moodle's course role assignment logic, where a user with teacher privileges could elevate their own permissions beyond the intended role boundaries within the course context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting Moodle (CVE-2020-14321). The exploit leverages a privilege escalation chain where a teacher can escalate their privileges to manager, add a system manager, use the 'loginas' feature to impersonate them, and reconfigure the system to allow plugin uploads. A malicious theme (plugin) is then uploaded, resulting in remote code execution (RCE) via a PHP payload (default: Meterpreter reverse shell). The module automates the entire attack chain, including privilege escalation, plugin upload, execution, and cleanup (removing the malicious theme and resetting permissions). The exploit requires valid teacher credentials and a vulnerable Moodle version. The main attack vector is HTTP requests to the Moodle web application, and the module interacts with several endpoints such as '/user/profile.php', '/user/index.php', and '/admin/search.php'. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and easy to use for attackers.
This repository provides a Python proof-of-concept exploit for CVE-2020-14321, a privilege escalation and remote code execution vulnerability in Moodle. The exploit consists of a single Python script (cve202014321.py) and a detailed README.md. The script automates the process of logging in as a teacher (using credentials or a session cookie), escalating privileges to a manager role within a course, and then leveraging this access to install a malicious plugin that enables remote command execution via HTTP requests. The exploit requires access to a vulnerable Moodle instance and valid teacher credentials or a session cookie. The README provides usage instructions, a Docker environment for testing, and additional resources. The main attack vector is network-based, targeting Moodle's web interface. Several HTTP endpoints are fingerprintable, including login, profile, enrolment, plugin installation, and the RCE trigger endpoint. The exploit is operational, providing a working end-to-end attack chain from privilege escalation to arbitrary command execution.
This repository contains a modified exploit for CVE-2020-14321, targeting Moodle's improper access control in course management. The main exploit is implemented in 'cve202014321.py', a Python script that automates privilege escalation from a teacher account to a manager (admin) role within a Moodle course. The script requires the target Moodle URL and a valid session cookie (or credentials) for a teacher account. It performs a series of HTTP requests to Moodle endpoints to manipulate user roles and impersonate higher-privileged users. The README provides usage instructions and example output, including evidence of successful privilege escalation. The exploit is operational and can be used to gain administrative access to vulnerable Moodle instances. The repository structure is simple, with one code file and a detailed README.
This repository contains a Python exploit script (CVE-2020-14321_RCE.py) and a README for CVE-2020-14321, a vulnerability in Moodle 3.9. The exploit targets a flaw where a teacher can escalate privileges to manager within a course, then leverage those permissions to install a malicious plugin, ultimately achieving remote command execution (RCE) as the web server user. The script automates the process: it logs in as a teacher (using credentials or a session cookie), escalates privileges, enables plugin installation, uploads a malicious zip file, and then executes arbitrary commands via a web-accessible PHP endpoint. The README provides usage instructions and example output. The exploit is operational, requiring valid teacher access and a vulnerable Moodle 3.9 instance. Key endpoints include login, user verification, plugin installation, and the RCE trigger endpoint exposed by the malicious plugin.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.