CVE-2015-3174: XSS
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISKXSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3174?
The severity of CVE-2015-3174 is classified as medium due to potential cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2015-3174?
To fix CVE-2015-3174, update Moodle to version 2.8.6, 2.7.8, or 2.6.11 or higher.
What impact does CVE-2015-3174 have on users?
CVE-2015-3174 allows remote authenticated users to exploit the vulnerability through crafted feedback in quiz grading, potentially leading to XSS attacks.
Which versions are affected by CVE-2015-3174?
CVE-2015-3174 affects Moodle versions prior to 2.5.10, 2.6.11, 2.7.8, and 2.8.6.
Is there a workaround for CVE-2015-3174?
There is no official workaround for CVE-2015-3174; updating to a patched version is the recommended solution.