Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2016-02-22T02:00:00
Updated: 2024-08-06T05:39:32.093Z
Reserved: 2015-04-10T00:00:00
Link: CVE-2015-3275
Vulnrichment
No data.
NVD
Status : Modified
Published: 2016-02-22T05:59:03.113
Modified: 2020-12-01T14:54:45.183
Link: CVE-2015-3275
Redhat
No data.