CVE-2015-2273: XSS
Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statisticsquestiontable.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the student role for a crafted quiz response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2273?
The severity of CVE-2015-2273 is considered medium as it allows remote authenticated users to inject arbitrary web scripts or HTML.
How do I fix CVE-2015-2273?
To fix CVE-2015-2273, upgrade Moodle to version 2.6.9, 2.7.6, or 2.8.4 or later.
Which versions of Moodle are affected by CVE-2015-2273?
Moodle versions from 2.5.0 up to 2.5.9, and 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 are affected.
What type of vulnerability is CVE-2015-2273?
CVE-2015-2273 is a cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2015-2273?
CVE-2015-2273 can be exploited by remote authenticated users leveraging the student role.