H5P metadata automatically populated the author with the user's username, which could be sensitive information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78820 | patch |
https://bugzilla.redhat.com/show_bug.cgi?id=2243444 | patch issue tracking |
https://moodle.org/mod/forum/discuss.php?d=451586 | patch vendor advisory |