PT-2016-1294 · Moodle · Moodle

Brian Winstead

·

Published

2015-09-23

·

Updated

2022-05-13

·

CVE-2015-5266

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 2.6.11 Moodle versions 2.7.x before 2.7.10 Moodle versions 2.8.x before 2.8.8 Moodle versions 2.9.x before 2.9.2
Description The issue is related to the enrol meta sync function in enrol/meta/locallib.php, which allows remote authenticated users to obtain manager privileges by leveraging incorrect role processing during a long-running sync script. This is due to insufficient access control, enabling an attacker to exploit the vulnerability and elevate their privileges.
Recommendations For versions prior to 2.6.11, update to version 2.6.11 or later. For versions 2.7.x before 2.7.10, update to version 2.7.10 or later. For versions 2.8.x before 2.8.8, update to version 2.8.8 or later. For versions 2.9.x before 2.9.2, update to version 2.9.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00591
CVE-2015-5266
GHSA-454R-4CJV-VC9H
MGASA-2015-0381

Affected Products

Moodle