CVE-2023-5545
09.11.2023, 20:15
H5P metadata automatically populated the author with the user's username, which could be sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 3.9.24 |
moodle | moodle | 3.11.0 ≤ 𝑥 < 3.11.17 |
moodle | moodle | 4.0.0 ≤ 𝑥 < 4.0.11 |
moodle | moodle | 4.1.0 ≤ 𝑥 < 4.1.6 |
moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.3 |
fedoraproject | extra_packages_for_enterprise_linux | 7.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References