CVE-2015-5264

MEDIUM

Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Auth Bypass

Title source: llm

Description

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 47.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-264
Status draft

Affected Products (22)

moodle/moodle < 2.6.11
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 7 more

Timeline

Published Feb 22, 2016
Tracked Since Feb 18, 2026