CVE-2015-5269: XSS
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5269?
CVE-2015-5269 has a moderate severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-5269?
To fix CVE-2015-5269, upgrade Moodle to version 2.7.10, 2.8.8, or 2.9.2 or later.
Who is affected by CVE-2015-5269?
CVE-2015-5269 affects users of Moodle versions prior to 2.7.10, 2.8.8, and 2.9.2.
What kind of vulnerability is CVE-2015-5269?
CVE-2015-5269 is a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts.
Can CVE-2015-5269 impact my Moodle site?
Yes, CVE-2015-5269 can impact Moodle sites by allowing attackers to execute arbitrary scripts in the context of users' sessions.