ZeroHour

CVE-2020-1754

CVSS 3.1
4.3 medium
EPSS
<1%p49
Published
()
Modified
Description

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

Vendors
moodle
Products
moodle
Weakness
CWE-284, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.