CVE-2022-40316
published 2022-09-30CVE-2022-40316: The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users…
PriorityP419medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.55%
42.3th percentile
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| moodle | moodle | — | — |
| moodle | moodle | >= 3.11 < 3.11.10 | 3.11.10 |
| moodle | moodle | >= 3.11.0 < 3.11.10 | 3.11.10 |
| moodle | moodle | >= 3.9 < 3.9.17 | 3.9.17 |
| moodle | moodle | >= 3.9.0 < 3.9.17 | 3.9.17 |
| moodle | moodle | >= 4.0 < 4.0.4 | 4.0.4 |
| moodle | moodle | >= 4.0.0 < 4.0.4 | 4.0.4 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moodle No groups filtering in H5P activity attempts report
ghsa·2022-10-01
CVE-2022-40316 [MEDIUM] CWE-668 Moodle No groups filtering in H5P activity attempts report
Moodle No groups filtering in H5P activity attempts report
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
OSV
Moodle No groups filtering in H5P activity attempts report
osv·2022-10-01
CVE-2022-40316 [MEDIUM] Moodle No groups filtering in H5P activity attempts report
Moodle No groups filtering in H5P activity attempts report
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
OSV
CVE-2022-40316: The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attemp
osv·2022-09-30·CVSS 4.3
CVE-2022-40316 [MEDIUM] CVE-2022-40316: The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attemp
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-30
Published