Security Advisory

CVE-2015-0216

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-06-01 19:00:00
Last updated 2024-08-06 04:03:10
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.