CVE-2015-5266
MEDIUMMoodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Privilege Escalation
Title source: llmDescription
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.
References (4)
Scores
CVSS v3
6.8
EPSS
0.0025
EPSS Percentile
47.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-264
Status
draft
Affected Products (22)
moodle/moodle
< 2.6.11
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 7 more
Timeline
Published
Feb 22, 2016
Tracked Since
Feb 18, 2026