Incorrect Permission Assignment for Critical Resource
CVE-2020-1754
Summary
In Moodle prior to 3.5.11, 3.6.x prior to 3.6.9, 3.7.x prior to 3.7.5, and 3.8.x prior to 3.8.2, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- LOW
- NONE
CWE-732 - Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Advisory Timeline
- Published