CVE-2022-40316: SQL Injection
Severity/Risk: Minor Versions affected: 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions Versions fixed: 4.0.4, 3.11.10 and 3.9.17 Reported by: Jari Vilkman and Bjørn Teistung Workaround: Access to this feature can be revoked by removing the mod/h5pactivity:reviewattempts capability from relevant users until the patch is applied. CVE identifier: CVE-2022-40316 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71662 http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72012 Tracker issue: MDL-71662 and MDL-72012 No groups filtering in H5P activity attempts report
Other sources
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.9.17 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 3.11.10 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 3.9.17 - Configuration
As a workaround until the patch is applied, revoke access by removing the mod/h5pactivity:reviewattempts capability from relevant users.
Moodle mod/h5pactivity capability mod/h5pactivity:reviewattempts = remove from relevant users
Event History
Frequently Asked Questions
What is CVE-2022-40316?
CVE-2022-40316 is a vulnerability in the H5P activity attempts report in Moodle, which allows non-editing teachers to access information about attempts/users in groups they should not have access to.
What is the severity of CVE-2022-40316?
CVE-2022-40316 has a severity rating of 4.3 (medium).
Which software versions are affected by CVE-2022-40316?
CVE-2022-40316 affects Moodle versions 3.9.0 to 3.9.17, 3.11.0 to 3.11.10, and 4.0.0 to 4.0.4.
How can non-editing teachers exploit CVE-2022-40316?
Non-editing teachers can exploit CVE-2022-40316 by accessing the H5P activity attempts report in Moodle, bypassing group restrictions and gaining unauthorized access to information.
How can CVE-2022-40316 be fixed?
To fix CVE-2022-40316, update your Moodle installation to a version that includes the necessary security patches.