Security Advisory

CVE-2015-3178

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-06-01 19:00:00
Last updated 2024-08-06 05:39:32
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.