VDB
Sign up
MEDIUM5.3

GHSA-26fg-v32r-h663

Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Quick fix

GHSA-26fg-v32r-h663 — moodle/moodle: upgrade to the fixed version with the command below.

composer require moodle/moodle:^4.3.0-rc2

Details

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/moodle/moodle
Introduced in: 0Fixed in: 4.3.0-rc2
Fixcomposer require moodle/moodle:^4.3.0-rc2

References