CVE-2015-5337: XSS
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5337?
The severity of CVE-2015-5337 is classified as medium due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2015-5337?
To fix CVE-2015-5337, upgrade Moodle to version 2.7.11, 2.8.9, or 2.9.3 or later.
What versions of Moodle are affected by CVE-2015-5337?
CVE-2015-5337 affects Moodle versions up to 2.6.11 and Moodle 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3.
What type of attack is possible with CVE-2015-5337?
CVE-2015-5337 allows remote attackers to conduct cross-site scripting (XSS) attacks using a crafted .swf file.
Is there a workaround for CVE-2015-5337?
There are no known workarounds for CVE-2015-5337; the best mitigation is to update to the patched versions.