CVE-2015-5266

MEDIUM

Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Privilege Escalation

Title source: llm

Description

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

Scores

CVSS v3 6.8
EPSS 0.0025
EPSS Percentile 47.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-264
Status draft

Affected Products (22)

moodle/moodle < 2.6.11
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 7 more

Timeline

Published Feb 22, 2016
Tracked Since Feb 18, 2026