A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
{
"severity": "Critical",
"cpes": [
"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
]
}