CVE-2015-2273

Moodle < 2.5.9 and 2.6.x < 2.6.9 - Authenticated Cross-Site Scripting via Quiz Response

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statistics_question_table.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the student role for a crafted quiz response.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=307387
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2015/03/16/1

Scores

EPSS 0.0021
EPSS Percentile 43.1%

Details

CWE
CWE-79
Status published
Products (30)
moodle/moodle 2.5.0
moodle/moodle 2.5.1
moodle/moodle 2.5.2
moodle/moodle 2.5.3
moodle/moodle 2.5.4
moodle/moodle 2.5.5
moodle/moodle 2.5.6
moodle/moodle 2.5.7
moodle/moodle 2.5.8
moodle/moodle 2.6.0
... and 20 more
Published Jun 01, 2015
Tracked Since Feb 18, 2026