CVE-2015-2269
Moodle < 2.5.9, 2.6.x < 2.6.9, 2.7.x < 2.7.6, 2.8.x < 2.8.4 - XSS via IMG Alt/Title
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2269. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates persistent XSS vulnerabilities in Moodle versions 2.5.9, 2.6.8, 2.7.5, and 2.8.3. The PoC shows how unsanitized input in POST parameters like 'config_title' and 'title' can execute arbitrary JavaScript in a user's browser session.
Description
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.
Exploits (1)
This exploit demonstrates persistent XSS vulnerabilities in Moodle versions 2.5.9, 2.6.8, 2.7.5, and 2.8.3. The PoC shows how unsanitized input in POST parameters like 'config_title' and 'title' can execute arbitrary JavaScript in a user's browser session.