CVE-2020-1754: Moodle
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
Affected products
- Moodle Moodle: from 3.5.0, before 3.5.11 (fixed in 3.5.11); from 3.6.0, before 3.6.9 (fixed in 3.6.9); from 3.7.0, before 3.7.5 (fixed in 3.7.5); version 3.8.0 only; version 3.8.1 only
Published 2022-08-05. Last modified 2026-06-23.