Medium severity5.4NVD Advisory· Published Feb 22, 2016· Updated Jun 17, 2026
CVE-2015-5264
CVE-2015-5264
Description
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 2.7.0, < 2.7.10 | 2.7.10 |
moodle/moodlePackagist | >= 2.8.0, < 2.8.8 | 2.8.8 |
moodle/moodlePackagist | >= 2.9.0, < 2.9.2 | 2.9.2 |
Affected products
22cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*+ 20 more
- cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*range: <=2.6.11
- cpe:2.3:a:moodle:moodle:2.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.5:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.6:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.7:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.8:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.7.9:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.5:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.8.7:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.9.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
16- github.com/advisories/GHSA-mm9q-3847-m48xghsaADVISORY
- moodle.org/mod/forum/discuss.phpnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2015-5264ghsaADVISORY
- www.openwall.com/lists/oss-security/2015/09/21/1nvdWEB
- github.com/moodle/moodle/commit/3071f085918dfeabb154596362dab2648ec6ad84ghsaWEB
- github.com/moodle/moodle/commit/343ed5b929ff8a68efe076505cd3e52d951f7869ghsaWEB
- github.com/moodle/moodle/commit/39b50f7d3eea43266a3d0c09590e48624e69a091ghsaWEB
- github.com/moodle/moodle/commit/67e3f70bb11382fc0f1eaf1a160c349269e370ccghsaWEB
- github.com/moodle/moodle/commit/9d5b339126586eddeced463c81295146e231a3c4ghsaWEB
- github.com/moodle/moodle/commit/9fd13426926fd882d3f024cb7171802ef2b3814dghsaWEB
- github.com/moodle/moodle/commit/ca74203efd51be6467091d9af762a31a7cad5840ghsaWEB
- github.com/moodle/moodle/commit/cd3a6a78b67abf5c9eb355ddc7899b1b2a9b20acghsaWEB
- github.com/moodle/moodle/commit/e7288eaabe77e04157f702b20fd0a7e9ce7067caghsaWEB
- github.com/moodle/moodle/commit/f9cc721dfd761ee34209cf58838079b9b550b356ghsaWEB
- web.archive.org/web/20160323063809/http://www.securitytracker.com/id/1033619ghsaWEB
- www.securitytracker.com/id/1033619nvd
News mentions
0No linked articles in our index yet.