Exposure of Resource to Wrong Sphere
CVE-2022-40316
Summary
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. This issue affects moodle versions through 3.9.16, 3.10.0-beta through 3.11.9, and 4.0.0-beta through 4.0.3.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- LOW
- NONE
CWE-668 - Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Advisory Timeline
- Published