CVE-2015-3178 Information
Feb 14, 2021
cve
Description
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9 2.6.x before 2.6.11 2.7.x before 2.7.8 and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.
Reference
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-49718 http://openwall.com/lists/oss-security/2015/05/18/1 http://www.securityfocus.com/bid/74726 http://www.securitytracker.com/id/1032358 https://moodle.org/mod/forum/discuss.php?d=313685
Share on: