CVE-2015-3274: XSS
Cross-site scripting (XSS) vulnerability in the usergetuserdetails function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an externalformattext call in a web service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3274?
CVE-2015-3274 is considered a high severity vulnerability due to its potential for remote code execution via cross-site scripting (XSS).
How do I fix CVE-2015-3274?
To fix CVE-2015-3274, upgrade to Moodle versions 2.7.9, 2.8.7, or 2.9.1 or later, for a secure resolution.
Who is affected by CVE-2015-3274?
CVE-2015-3274 affects Moodle versions 2.6 through 2.9 prior to their respective patches.
What type of vulnerability is CVE-2015-3274?
CVE-2015-3274 is a cross-site scripting (XSS) vulnerability which allows attackers to inject malicious scripts into web pages.
Can CVE-2015-3274 allow unauthorized access?
Yes, CVE-2015-3274 can potentially allow unauthorized attackers to execute scripts in a user's browser session.