The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2016-02-22T02:00:00

Updated: 2024-08-06T06:41:09.238Z

Reserved: 2015-07-01T00:00:00

Link: CVE-2015-5266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-02-22T05:59:06.300

Modified: 2020-12-01T14:54:45.183

Link: CVE-2015-5266

cve-icon Redhat

No data.