CVE-2014-3617: Medium severity moodle vulnerability
The forumprintlatestdiscussions function in mod/forum/lib.php in Moodle through 2.4.11, 2.5.x before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2 allows remote authenticated users to bypass the individual answer-posting requirement without the mod/forum:viewqandawithoutposting capability, and discover an author's username, by leveraging the student role and visiting a Q&A forum.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3617?
CVE-2014-3617 is considered a medium severity vulnerability as it allows remote authenticated users to bypass security controls in Moodle.
How do I fix CVE-2014-3617?
To resolve CVE-2014-3617, update your Moodle installation to at least version 2.5.8, 2.6.5, or 2.7.2.
Which versions of Moodle are affected by CVE-2014-3617?
The affected versions of Moodle include 2.0.x, 2.1.x, 2.2.x, 2.3.x, 2.4.x through 2.4.11, and 2.5.x prior to 2.5.8.
What can exploit CVE-2014-3617?
CVE-2014-3617 can be exploited by remote authenticated users who can bypass the individual answer-posting requirement.
What functionality does CVE-2014-3617 compromise?
CVE-2014-3617 compromises the ability to enforce the individual answer-posting requirement for discussions in Moodle forums.