CVE-2015-5336: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5336?
CVE-2015-5336 has been rated as a medium severity vulnerability.
How do I fix CVE-2015-5336?
To fix CVE-2015-5336, update your Moodle installation to version 2.7.11, 2.8.9, or 2.9.3 or later.
What versions of Moodle are affected by CVE-2015-5336?
CVE-2015-5336 affects Moodle versions up to 2.6.11, all 2.7.x versions before 2.7.11, all 2.8.x versions before 2.8.9, and all 2.9.x versions before 2.9.3.
What types of attacks can CVE-2015-5336 allow?
CVE-2015-5336 can allow remote authenticated users to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Who can exploit CVE-2015-5336?
CVE-2015-5336 can be exploited by authenticated users with student roles within the Moodle environment.