CVE-2014-7831: Infoleak
lib/classes/gradesexternal.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the getgrades web service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7831?
The severity of CVE-2014-7831 is classified as medium, allowing remote authenticated users to access hidden grades.
How do I fix CVE-2014-7831?
To fix CVE-2014-7831, upgrade your Moodle installation to version 2.7.3 or higher.
Which versions of Moodle are affected by CVE-2014-7831?
CVE-2014-7831 affects Moodle versions 2.7.0 to 2.7.2, along with multiple earlier versions.
What can attackers do with CVE-2014-7831?
Attackers exploiting CVE-2014-7831 can access sensitive hidden grades by leveraging the student role.
Is there a workaround for CVE-2014-7831 until I can apply a fix?
There is no known workaround for CVE-2014-7831; the best mitigation is to update to the latest version.