CVE-2014-7834 PUBLISHED CVSS 4 MEDIUM

mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

EPSS 0.19% · 40.8th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.19%
40.8th percentile

Affected Products

VendorProductVersions
moodlemoodle2.6.0, 2.7.0
n/an/an/a
moodlemoodle2.5.1, 2.5.2, 2.5.3

Timeline

References

…and 1 more

Open in Interactive Console →