Insufficient handling of access control checks in the course_output_fragment_course_overview() function allows information about restricted courses to be returned to users lacking proper permissions. An attacker with a valid Moodle account could exploit this to view metadata about inaccessible courses. Versions affected: 5.0 to 5.0.2 Versions fixed: 5.0.3