Skip to main content

Incorrect Permission Assignment for Critical Resource

CVE-2020-1754

Severity Medium
Score 4.3/10

Summary

In Moodle prior to 3.5.11, 3.6.x prior to 3.6.9, 3.7.x prior to 3.7.5, and 3.8.x prior to 3.8.2, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-732 - Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Advisory Timeline

  • Published