GHSA-26fg-v32r-h663
GitHub Security Advisory
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
Affected Packages
Packagist
moodle/moodle
Affected versions:
0
(fixed in 4.3.0-rc2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.