CVE-2015-3178: XSS
Cross-site scripting (XSS) vulnerability in the externalformattext function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3178?
CVE-2015-3178 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2015-3178?
To fix CVE-2015-3178, update Moodle to version 2.6.11, 2.7.8, or 2.8.6 or later.
Which versions of Moodle are affected by CVE-2015-3178?
CVE-2015-3178 affects Moodle versions up to and including 2.5.9, all 2.6.x versions before 2.6.11, all 2.7.x versions before 2.7.8, and all 2.8.x versions before 2.8.6.
What type of vulnerability is CVE-2015-3178?
CVE-2015-3178 is a cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2015-3178?
CVE-2015-3178 can be exploited by remote authenticated users.