First published: Mon Feb 22 2016(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=2.9.0<2.9.1 | 2.9.1 |
composer/moodle/moodle | >=2.8.0<2.8.7 | 2.8.7 |
composer/moodle/moodle | >=2.7.0<2.7.9 | 2.7.9 |
Moodle | <=2.6.11 | |
Moodle | =2.7.0 | |
Moodle | =2.7.1 | |
Moodle | =2.7.2 | |
Moodle | =2.7.3 | |
Moodle | =2.7.4 | |
Moodle | =2.7.5 | |
Moodle | =2.7.6 | |
Moodle | =2.7.7 | |
Moodle | =2.7.8 | |
Moodle | =2.7.9 | |
Moodle | =2.8.0 | |
Moodle | =2.8.1 | |
Moodle | =2.8.2 | |
Moodle | =2.8.3 | |
Moodle | =2.8.4 | |
Moodle | =2.8.5 | |
Moodle | =2.8.6 | |
Moodle | =2.8.7 | |
Moodle | =2.9.0 | |
Moodle | =2.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3275 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2015-3275, upgrade your Moodle installation to version 2.7.9, 2.8.7, or 2.9.1.
CVE-2015-3275 affects Moodle versions 2.6.11 and earlier, as well as 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1.
CVE-2015-3275 allows remote attackers to inject arbitrary web scripts or HTML through crafted organization names.
CVE-2015-3275 impacts the SCORM module, specifically files like mod/scorm/player.php.