GHSA-6922-5v25-p8jg
Dashboard / Vulnerabilities / GHSA-6922-5v25-p8jg
Summary: Moodle multiple cross-site scripting (XSS) vulnerabilities
Details: Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-3275, https://github.com/moodle/moodle/commit/46460a23035ad35caa50c2083ce6327f7723002e, https://github.com/moodle/moodle/commit/476e97f280f5fa146f3ab676dd6f07de481ad9e8, https://github.com/moodle/moodle/commit/d942f0311c0d4d8200b9d3244cc8847046abc32e, https://github.com/moodle/moodle/commit/f3e7afedb96e2637a30d9bebd5fa98d45eca5f55, https://github.com/moodle/moodle, https://moodle.org/mod/forum/discuss.php?d=316665, https://web.archive.org/web/20150924032214/http://www.securitytracker.com/id/1032877, http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50614, http://openwall.com/lists/oss-security/2015/07/13/2
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: ECOSYSTEM
Events:
