Description
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.
Remediation
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-13258)
Magento Improper Authorization Vulnerability (CVE-2020-24402)
WordPress Plugin Titan Framework Cross-Site Scripting (1.12.1)
Artifactory CVE-2020-7931 Vulnerability (CVE-2020-7931)
WordPress Plugin VikBooking Hotel Booking Engine & PMS Cross-Site Scripting (1.5.8)