5.3
CVE-2024-25980
- EPSS 0.17%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:47:04
- Quelle patrick@puiterwijk.org
- CVE-Watchlists
- Unerledigt
Msa-24-0003: h5p attempts report did not respect activity group settings
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.38 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| patrick@puiterwijk.org | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.