CVE-2015-5266
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.
La función enrol_meta_sync en enrol/meta/locallib.php en Moodle hasta la versión 2.6.11, 2.7.x en versiones anteriores a 2.7.10, 2.8.x en versiones anteriores a 2.8.8 y 2.9.x en versiones anteriores a 2.9.2 permite a usuarios remotos autenticados obtener privilegios de administrador en circunstancias oportunistas aprovechando el procesado incorrecto del rol durante una secuencia de comandos de sincronización de larga duración.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-07-01 CVE Reserved
- 2016-02-22 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50744 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2015/09/21/1 | Mailing List | |
http://www.securitytracker.com/id/1033619 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://moodle.org/mod/forum/discuss.php?d=320290 | 2020-12-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | <= 2.6.11 Search vendor "Moodle" for product "Moodle" and version " <= 2.6.11" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.0 Search vendor "Moodle" for product "Moodle" and version "2.7.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.1 Search vendor "Moodle" for product "Moodle" and version "2.7.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.2 Search vendor "Moodle" for product "Moodle" and version "2.7.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.3 Search vendor "Moodle" for product "Moodle" and version "2.7.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.4 Search vendor "Moodle" for product "Moodle" and version "2.7.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.5 Search vendor "Moodle" for product "Moodle" and version "2.7.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.6 Search vendor "Moodle" for product "Moodle" and version "2.7.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.7 Search vendor "Moodle" for product "Moodle" and version "2.7.7" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.8 Search vendor "Moodle" for product "Moodle" and version "2.7.8" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.7.9 Search vendor "Moodle" for product "Moodle" and version "2.7.9" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.0 Search vendor "Moodle" for product "Moodle" and version "2.8.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.1 Search vendor "Moodle" for product "Moodle" and version "2.8.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.2 Search vendor "Moodle" for product "Moodle" and version "2.8.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.3 Search vendor "Moodle" for product "Moodle" and version "2.8.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.4 Search vendor "Moodle" for product "Moodle" and version "2.8.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.5 Search vendor "Moodle" for product "Moodle" and version "2.8.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.6 Search vendor "Moodle" for product "Moodle" and version "2.8.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.8.7 Search vendor "Moodle" for product "Moodle" and version "2.8.7" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.9.0 Search vendor "Moodle" for product "Moodle" and version "2.9.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.9.1 Search vendor "Moodle" for product "Moodle" and version "2.9.1" | - |
Affected
|