---
id: CVE-2020-1754
title: >-
  In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade
  history report without the 'access all groups' capability were not restricted
  to viewing grades of users within their own groups.
summary: >-
  In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade
  history report without the 'access all groups' capability were not restricted
  to viewing grades of users within their own groups.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-284
  - CWE-732
vendor: moodle
product: moodle
affected:
  - 'moodle >= 3.5.0, < 3.5.11'
  - 'moodle >= 3.6.0, < 3.6.9'
  - 'moodle >= 3.7.0, < 3.7.5'
  - moodle = 3.8.0
  - moodle = 3.8.1
patched:
  - moodle 3.7.5
published: '2022-08-05'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1754'
references:
  - url: 'https://moodle.org/mod/forum/discuss.php?d=398350'
    label: secalert@redhat.com
  - url: 'https://moodle.org/mod/forum/discuss.php?d=398350'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00641
epssPercentile: 0.4854
ingestedAt: '2026-06-29T13:24:33.495Z'
---

## Overview

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

## Affected

- `moodle >= 3.5.0, < 3.5.11`
- `moodle >= 3.6.0, < 3.6.9`
- `moodle >= 3.7.0, < 3.7.5`
- `moodle = 3.8.0`
- `moodle = 3.8.1`

## Remediation

Upgrade past the affected range:

- `moodle 3.7.5`
