A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
https://github.com/voniem12/KTLHPM
https://github.com/advisories/GHSA-6jhm-4vmx-mr76