MGASA-2015-0302

Source
https://advisories.mageia.org/MGASA-2015-0302.html
Import Source
https://advisories.mageia.org/MGASA-2015-0302.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0302
Upstream
  • CVE-2015-3272
  • CVE-2015-3274
  • CVE-2015-3275
Published
2015-08-03T20:55:18Z
Modified
2026-04-16T06:24:43.877201253Z
Summary
Updated moodle package fixes security vulnerabilities
Details

In Moodle before 2.8.7, phishing is possible when redirecting to external site using referer headers in error messages (CVE-2015-3272).

In Moodle before 2.8.7, several web services returning user information did not clean text in text custom profile fields, leading to possible XSS (CVE-2015-3274).

In Moodle before 2.8.7, possible Javascript injection was discovered in the SCORM module (CVE-2015-3275).

As Moodle 2.6 is no longer supported, users of this package on Mageia 4 are advised to migrate to Mageia 5.

References
Credits

Affected packages

Mageia:5 / moodle

Package

Name
moodle
Purl
pkg:rpm/mageia/moodle?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.7-1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0302.json"