A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
https://github.com/voniem12/KTLHPM
https://github.com/advisories/GHSA-6jhm-4vmx-mr76
https://moodle.org/mod/forum/discuss.php?d=431099