MEDIUM
Moodle: auto-populated h5p author name causes a potential information leak
Published Nov 9, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.54%
Description
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 7.0
- 38
-
- Version 3.11StatusaffectedConstraints-
- Version 3.9StatusaffectedConstraints-
- Version 4.0StatusaffectedConstraints-
- Version 4.1StatusaffectedConstraints-
- Version 4.2StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78820 Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=2243444 issue-trackingx_refsource_REDHATIssue TrackingPatch
- https://github.com/advisories/GHSA-26fg-v32r-h663 Advisory
- https://github.com/moodle/moodle/commit/100ac7c6467a7de2c05713a0a924984ff1593d53
- https://moodle.org/mod/forum/discuss.php?d=451586 PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-5545
| Link | Providers | Tags |
|---|---|---|
| http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78820 | Patch | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2243444 | issue-trackingx_refsource_REDHATIssue TrackingPatch | |
| https://github.com/advisories/GHSA-26fg-v32r-h663 | Advisory | |
| https://github.com/moodle/moodle/commit/100ac7c6467a7de2c05713a0a924984ff1593d53 | ||
| https://moodle.org/mod/forum/discuss.php?d=451586 | PatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-5545 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Nov 9, 2023
Updated Aug 2, 2024
Reserved Oct 12, 2023
Link CVE-2023-5545
CISA Vulnrichment
GHSA-26FG-V32R-H663 Updated Apr 22, 2024