What the vulnerability does

01Description

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

Key dates

02Disclosure timeline

August 5, 2022 CVE published
August 4, 2024 Record updated