Feed/CVE-2015-0216
CVE-2015-0216LOWCVSS 3.5

CVE-2015-0216

Published Jun 1, 2015·Updated Jun 16, 2026

NVD Description

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVSS Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free