Description
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.
Remediation
References
Related Vulnerabilities
WordPress Improper Input Validation Vulnerability (CVE-2008-5695)
PostgreSQL CVE-2021-3677 Vulnerability (CVE-2021-3677)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0793)
Oracle Database Server CVE-2019-2484 Vulnerability (CVE-2019-2484)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.9.93)