#VU26117 Information disclosure in Moodle - CVE-2020-1754
Published: March 17, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the grade history report does not respect Separate groups mode in the course settings. A remote authenticated attacker viewing the grade history report without the "access all groups" capability can view sensitive information from other groups.