CVE-2023-5545
published 2023-11-09CVE-2023-5545: H5P metadata automatically populated the author with the user's username, which could be sensitive information.
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.54%
41.7th percentile
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| moodle | moodle | < 3.9.24 | 3.9.24 |
| moodle | moodle | >= 0 < 4.3.0-rc2 | 4.3.0-rc2 |
| moodle | moodle | >= 3.11.0 < 3.11.17 | 3.11.17 |
| moodle | moodle | >= 4.0.0 < 4.0.11 | 4.0.11 |
| moodle | moodle | >= 4.1.0 < 4.1.6 | 4.1.6 |
| moodle | moodle | >= 4.2.0 < 4.2.3 | 4.2.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
osv·2023-11-09
CVE-2023-5545 [MEDIUM] Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
OSV
CVE-2023-5545: H5P metadata automatically populated the author with the user's username, which could be sensitive information
osv·2023-11-09·CVSS 5.3
CVE-2023-5545 [MEDIUM] CVE-2023-5545: H5P metadata automatically populated the author with the user's username, which could be sensitive information
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
GHSA
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
ghsa·2023-11-09
CVE-2023-5545 [MEDIUM] CWE-200 Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78820https://bugzilla.redhat.com/show_bug.cgi?id=2243444https://moodle.org/mod/forum/discuss.php?d=451586http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78820https://bugzilla.redhat.com/show_bug.cgi?id=2243444https://moodle.org/mod/forum/discuss.php?d=451586
2023-11-09
Published