Description
mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.
Remediation
References
Related Vulnerabilities
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-6514)
WordPress Plugin LeagueManager SQL Injection (3.8)
CakePHP Improper Input Validation Vulnerability (CVE-2010-4335)
WordPress Plugin Sign-up Sheets Cross-Site Scripting (1.0.13)
Cherokee Improper Input Validation Vulnerability (CVE-2009-4489)