CVE-2014-7834: Medium severity moodle vulnerability
mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forumgetdiscussions web service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7834?
CVE-2014-7834 is considered a medium severity vulnerability due to improper verification of group permissions that can lead to unauthorized access.
What versions of Moodle are affected by CVE-2014-7834?
CVE-2014-7834 affects Moodle versions 2.6.x prior to 2.6.6 and 2.7.x prior to 2.7.3.
How do I fix CVE-2014-7834?
To fix CVE-2014-7834, upgrade to Moodle version 2.6.6 or later or 2.7.3 or later.
What causes the vulnerability in CVE-2014-7834?
The vulnerability in CVE-2014-7834 is caused by mod/forum/externallib.php not verifying group permissions when accessing the forum_get_discussions web service.
Can CVE-2014-7834 be exploited remotely?
Yes, CVE-2014-7834 can be exploited remotely by authenticated users to access forums they should not have permission to view.