PT-2023-32167 · H5P · H5P

Josh Manders

·

Published

2023-11-09

·

Updated

2024-07-03

·

CVE-2023-5545

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions H5P (affected versions not specified)
Description The issue concerns H5P metadata automatically populating the author field with the user's username, potentially exposing sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-MOODLE-2023-5545
CVE-2023-5545
GHSA-26FG-V32R-H663

Affected Products

H5P