CVE-2020-1754
05.08.2022, 16:15
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 3.5.0 ≤ 𝑥 < 3.5.11 |
moodle | moodle | 3.6.0 ≤ 𝑥 < 3.6.9 |
moodle | moodle | 3.7.0 ≤ 𝑥 < 3.7.5 |
moodle | moodle | 3.8.0 |
moodle | moodle | 3.8.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.