CVE-2014-3546: Medium severity moodle vulnerability
Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3546?
The severity of CVE-2014-3546 is moderate as it allows unauthorized access to potentially sensitive user information.
How do I fix CVE-2014-3546?
You can fix CVE-2014-3546 by upgrading to Moodle version 2.7.1 or applying the recommended patches for affected versions.
What versions of Moodle are affected by CVE-2014-3546?
CVE-2014-3546 affects Moodle versions through 2.3.11 and various versions up to 2.6.3, as well as 2.7.0 and earlier.
What kind of information can be exposed due to CVE-2014-3546?
CVE-2014-3546 can expose sensitive username and course information to remote attackers.
Is CVE-2014-3546 being actively exploited?
There have not been widespread reports of active exploitation specifically related to CVE-2014-3546, but patching is strongly recommended.