Lucene search

K
cveFedoraCVE-2024-25980
HistoryFeb 19, 2024 - 5:15 p.m.

CVE-2024-25980

2024-02-1917:15:09
CWE-284
fedora
web.nvd.nist.gov
68
cve
2024
25980
h5p
attempts report
security
nvd

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0

Percentile

15.5%

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CNA Affected

[
  {
    "versions": [
      {
        "status": "affected",
        "version": "4.3.0",
        "lessThan": "4.3.3",
        "versionType": "semver"
      },
      {
        "status": "affected",
        "version": "4.2.0",
        "lessThan": "4.2.6",
        "versionType": "semver"
      },
      {
        "status": "affected",
        "version": "0",
        "lessThan": "4.1.9",
        "versionType": "semver"
      }
    ],
    "packageName": "moodle",
    "collectionURL": "https://git.moodle.org",
    "defaultStatus": "unaffected"
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0

Percentile

15.5%