Description
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.
Remediation
References
Related Vulnerabilities
WebLogic Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2018-10237)
Atlassian Jira Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-41306)
WordPress Plugin Tutor LMS Elementor Addons Cross-Site Scripting (2.1.3)
WordPress Plugin MapSVG Lite Cross-Site Request Forgery (4.2.4)