CVE-2024-25980: Fedoraproject Fedora
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
Affected products
- Fedoraproject Fedora: version 38 only
- Moodle Moodle: from 4.1.0, before 4.1.9 (fixed in 4.1.9); from 4.2.0, before 4.2.6 (fixed in 4.2.6); from 4.3.0, before 4.3.3 (fixed in 4.3.3)
Published 2024-02-19. Last modified 2026-06-17.