3.5
CVSSv2

CVE-2015-0216

Published: 01/06/2015 Updated: 01/12/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

access.php in the Lesson module in Moodle 2.8.x prior to 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.8.0

moodle moodle 2.8.1