#VU67471 Permissions, Privileges, and Access Controls in Moodle - CVE-2022-40316
Published: September 19, 2022
Moodle
moodle.org
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to the H5P activity attempts report does not respect group permissions when displaying information to non-editing teachers about attempts/users in groups they should not have access to. A remote user can gain access to sensitive information.