Description
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2017-10336 Vulnerability (CVE-2017-10336)
WordPress Plugin Meta Box-WordPress Custom Fields Framework Arbitrary File Upload (4.16.1)
Django Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-33571)
phpList Other Vulnerability (CVE-2006-5524)
WordPress Plugin BP Group Documents Multiple Vulnerabilities (1.2.1)