CVE-2014-7837: Medium severity moodle vulnerability
mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7837?
CVE-2014-7837 is classified as a medium severity vulnerability, allowing remote authenticated users to delete wiki pages.
How do I fix CVE-2014-7837?
To fix CVE-2014-7837, upgrade Moodle to version 2.7.3, 2.6.6, or 2.5.9 or later.
Which versions of Moodle are affected by CVE-2014-7837?
CVE-2014-7837 affects Moodle versions 2.4.11 and lower, 2.5.0 through 2.5.8, 2.6.0 through 2.6.5, and 2.7.0 through 2.7.2.
What are the potential impacts of CVE-2014-7837?
The potential impact of CVE-2014-7837 allows unauthorized deletion of wiki pages in Moodle, which can lead to data loss.
Who can exploit CVE-2014-7837?
CVE-2014-7837 can be exploited by remote authenticated users with delete access in a different subwiki.