CVE-2015-5264: Medium severity moodle vulnerability
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5264?
CVE-2015-5264 has a medium severity rating due to its potential for access control bypass by authenticated users.
How do I fix CVE-2015-5264?
To fix CVE-2015-5264, upgrade to Moodle version 2.7.10, 2.8.8, or 2.9.2 or later.
Which versions of Moodle are affected by CVE-2015-5264?
CVE-2015-5264 affects Moodle versions 2.6.11 and earlier, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2.
What does CVE-2015-5264 allow attackers to do?
CVE-2015-5264 allows remote authenticated users to bypass access restrictions and submit additional answer attempts.
Is there a permanent solution for CVE-2015-5264?
Yes, the permanent solution is to keep Moodle updated to the latest version beyond the patched versions.