CVE-2020-1754
—CVSS 3.1
4.3 medium
EPSS
<1%p49
Published
()
Modified
Description
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
- Vendors
- moodle
- Products
- moodle
- Weakness
- CWE-284, CWE-732
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.