Skip to main content

Exposure of Resource to Wrong Sphere

CVE-2022-40316

Severity Medium
Score 4.3/10

Summary

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. This issue affects moodle versions through 3.9.16, 3.10.0-beta through 3.11.9, and 4.0.0-beta through 4.0.3.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Advisory Timeline

  • Published