CVE-2014-7832 PUBLISHED CVSS 4 MEDIUM

mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

EPSS 0.24% · 47.4th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.24%
47.4th percentile

Affected Products

VendorProductVersions
moodlemoodle2.7.2, 2.6.4, 2.6.5
n/an/an/a
moodlemoodle0, 2.6.0, 2.7.0

Timeline

References

…and 2 more

Open in Interactive Console →