CVE-2014-3546: Moodle
Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.
Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.
Affected products
- Moodle Moodle: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; version 2.6.3 only; up to and including 2.3.11; version 2.3.0 only; …
Published 2014-07-29. Last modified 2026-06-17.