VYPR
Medium severity4.3NVD Advisory· Published Aug 5, 2022· Updated Jun 23, 2026

CVE-2020-1754

CVE-2020-1754

Description

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

Affected products

6
  • Moodle/Moodle5 versions
    cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*range: >=3.5.0,<3.5.11
    • cpe:2.3:a:moodle:moodle:3.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:moodle:moodle:3.8.1:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: <3.8.2, <3.7.5, <3.6.9, <3.5.11
  • osv-coords
    Range: >= 3.5.0, < 3.5.11

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.