Looking for the vulnerability index of Invicti's legacy products?
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5266) - Vulnerability Database

Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5266)

Description

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

References

Related Vulnerabilities