PT-2014-8301 · Moodle · Moodle
Petr Skoda
·
Published
2014-11-22
·
Updated
2022-05-13
·
CVE-2014-7834
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle versions 2.6.x through 2.6.5
Moodle versions 2.7.x through 2.7.2
Description
The issue allows remote authenticated users to access a forum without proper group permission verification. This is due to a problem in the
mod/forum/externallib.php file, specifically with the forum get discussions web service.Recommendations
For Moodle versions 2.6.x through 2.6.5, update to version 2.6.6 or later.
For Moodle versions 2.7.x through 2.7.2, update to version 2.7.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moodle