CVE-2015-5264

MEDIUM

Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/21/1
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033619
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=320287

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-264
Status published
Products (22)
moodle/moodle 2.7.0
moodle/moodle 2.7.1
moodle/moodle 2.7.2
moodle/moodle 2.7.3
moodle/moodle 2.7.4
moodle/moodle 2.7.5
moodle/moodle 2.7.6
moodle/moodle 2.7.7
moodle/moodle 2.7.8
moodle/moodle 2.7.9
... and 12 more
Published Feb 22, 2016
Tracked Since Feb 18, 2026