Description
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
Remediation
References
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9735)
Oracle Application Server Other Vulnerability (CVE-2005-3449)
WordPress Plugin Ultimate Addons for Beaver Builder Cross-Site Scripting (1.24.3)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17308)
WordPress Plugin Limit Login Attempts Cross-Site Scripting (1.7.1)