PT-2022-5129 · H5P+3 · H5P+3
Bjørn Teistung
+1
·
Published
2020-11-08
·
Updated
2025-05-20
·
CVE-2022-40316
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moodle (affected versions not specified)
Description
The issue is related to the H5P plugin in the Moodle virtual learning environment, where the H5P activity attempts report does not filter by groups. This can reveal information to non-editing teachers about attempts or users in groups they should not have access to, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Code Injection
RCE
Exposure of Resource to Wrong Sphere
Path traversal
SQL injection
Missing Authorization
Open Redirect
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
H5P
Moodle
Red Os