Description
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2020-2773 Vulnerability (CVE-2020-2773)
OpenSSL Improper Access Control Vulnerability (CVE-2016-7054)
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (7.1.04)
WordPress Plugin Meteor Slides Cross-Site Scripting (1.5.6)
WordPress Plugin Spryng Payments for WooCommerce Cross-Site Scripting (1.6.7)