First published: Mon Jun 01 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=2.8.0<2.8.4 | 2.8.4 |
composer/moodle/moodle | >=2.7.0<2.7.6 | 2.7.6 |
composer/moodle/moodle | >=2.6.0<2.6.9 | 2.6.9 |
composer/moodle/moodle | <=2.5.9 | |
Moodle | <=2.5.9 | |
Moodle | =2.5.0 | |
Moodle | =2.5.1 | |
Moodle | =2.5.2 | |
Moodle | =2.5.3 | |
Moodle | =2.5.4 | |
Moodle | =2.5.5 | |
Moodle | =2.5.6 | |
Moodle | =2.5.7 | |
Moodle | =2.5.8 | |
Moodle | =2.6.0 | |
Moodle | =2.6.1 | |
Moodle | =2.6.2 | |
Moodle | =2.6.3 | |
Moodle | =2.6.4 | |
Moodle | =2.6.5 | |
Moodle | =2.6.6 | |
Moodle | =2.6.7 | |
Moodle | =2.6.8 | |
Moodle | =2.7.0 | |
Moodle | =2.7.1 | |
Moodle | =2.7.2 | |
Moodle | =2.7.3 | |
Moodle | =2.7.4 | |
Moodle | =2.7.5 | |
Moodle | =2.8.0 | |
Moodle | =2.8.1 | |
Moodle | =2.8.2 | |
Moodle | =2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2269 is considered a medium severity vulnerability due to its potential for remote authenticated XSS attacks.
To resolve CVE-2015-2269, upgrade Moodle to version 2.6.9, 2.7.6, or 2.8.4 or later.
CVE-2015-2269 affects Moodle versions 2.5.9 and earlier, all 2.6.x versions before 2.6.9, all 2.7.x versions before 2.7.6, and all 2.8.x versions before 2.8.4.
CVE-2015-2269 can allow remote authenticated users to inject arbitrary web scripts or HTML through the alt or title attributes in IMG elements.
You can determine if your Moodle installation is vulnerable to CVE-2015-2269 by checking the version number against the affected versions listed.