Looking for the vulnerability index of Invicti's legacy products?
Moodle Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-1754) - Vulnerability Database

Moodle Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-1754)

Description

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

References

Related Vulnerabilities