CVE-2015-5266: Medium severity moodle vulnerability
The enrolmetasync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5266?
CVE-2015-5266 has a severity rating that indicates it allows remote authenticated users to gain manager privileges under certain conditions.
How do I fix CVE-2015-5266?
To fix CVE-2015-5266, update your Moodle installation to version 2.7.10, 2.8.8, or 2.9.2 or later.
Which versions of Moodle are affected by CVE-2015-5266?
CVE-2015-5266 affects Moodle versions up to 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2.
Who is at risk from CVE-2015-5266?
Remote authenticated users in Moodle installations that have not been patched are at risk from CVE-2015-5266.
What impact does CVE-2015-5266 have on Moodle installations?
CVE-2015-5266 can lead to unauthorized escalation of privileges, allowing users to obtain manager access.