CVE-2015-3275: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3275?
CVE-2015-3275 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-3275?
To fix CVE-2015-3275, upgrade your Moodle installation to version 2.7.9, 2.8.7, or 2.9.1.
What versions of Moodle are affected by CVE-2015-3275?
CVE-2015-3275 affects Moodle versions 2.6.11 and earlier, as well as 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1.
What types of attacks are possible with CVE-2015-3275?
CVE-2015-3275 allows remote attackers to inject arbitrary web scripts or HTML through crafted organization names.
What components in Moodle are impacted by CVE-2015-3275?
CVE-2015-3275 impacts the SCORM module, specifically files like mod/scorm/player.php.