Exposure of Resource to Wrong Sphere
CVE-2023-5545
Summary
H5P metadata automatically populated the author with the user's "username", which could leads to an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. This vulnerability affects moodle/moodle package versions through 3.9.23, 3.10.0-beta through 3.11.16, 4.0.0-beta through 4.0.10, 4.1.0-beta through 4.1.5, 4.2.0-beta through 4.2.2, and 4.3.0-beta through 4.3.0-rc1.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-668 - Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Advisory Timeline
- Published