CVE-2014-7832: Medium severity moodle vulnerability
mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7832?
CVE-2014-7832 has a medium severity rating due to improper access control at the course level.
How do I fix CVE-2014-7832?
To fix CVE-2014-7832, upgrade Moodle to version 2.5.9, 2.6.6, or 2.7.3 or later.
Who is affected by CVE-2014-7832?
All users of Moodle versions 2.4.11, 2.5.x below 2.5.9, 2.6.x below 2.6.6, and 2.7.x below 2.7.3 are affected by CVE-2014-7832.
What type of vulnerability is CVE-2014-7832?
CVE-2014-7832 is an access control vulnerability that allows remote authenticated users to bypass security measures.
What components of Moodle are implicated in CVE-2014-7832?
CVE-2014-7832 specifically involves the LTI module, particularly the mod/lti/launch.php file.