Skip to main content

Exposure of Resource to Wrong Sphere

CVE-2023-5545

Severity Medium
Score 5.3/10

Summary

H5P metadata automatically populated the author with the user's "username", which could leads to an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. This vulnerability affects moodle/moodle package versions through 3.9.23, 3.10.0-beta through 3.11.16, 4.0.0-beta through 4.0.10, 4.1.0-beta through 4.1.5, 4.2.0-beta through 4.2.2, and 4.3.0-beta through 4.3.0-rc1.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Advisory Timeline

  • Published