The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2128151 | issue tracking third party advisory patch |
https://moodle.org/mod/forum/discuss.php?d=438395 | patch vendor advisory |