Moodle · Moodle · CVE-2021-20184
**Name of the Vulnerable Software and Affected Versions**
Moodle versions prior to 3.10.1
Moodle versions prior to 3.9.4
Moodle versions prior to 3.8.7
**Description**
The issue is related to insufficient capability checks in some grade-related web services, allowing students to view other students' grades. This is due to flaws in access control within the "Gradebook" module of the Moodle virtual learning environment. Exploitation of this issue can allow a remote attacker to gain unauthorized access to protected information.
**Recommendations**
For versions prior to 3.10.1, update to version 3.10.1 or later.
For versions prior to 3.9.4, update to version 3.9.4 or later.
For versions prior to 3.8.7, update to version 3.8.7 or later.