A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.