FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

moodle -- multiple vulnerabilities

Affected packages
moodle27 < 2.7.9
moodle28 < 2.8.7
moodle29 < 2.9.1

Details

VuXML ID 43891162-2d5e-11e5-a4a5-002590263bf5
Discovery 2015-07-06
Entry 2015-07-18
Modified 2015-07-19

Marina Glancy reports:

MSA-15-0026: Possible phishing when redirecting to external site using referer header. (CVE-2015-3272)

MSA-15-0027: Capability 'mod/forum:canposttomygroups' is not respected when using 'Post a copy to all groups' in forum (CVE-2015-3273)

MSA-15-0028: Possible XSS through custom text profile fields in Web Services (CVE-2015-3274)

MSA-15-0029: Javascript injection in SCORM module (CVE-2015-3275)

References

CVE Name CVE-2015-3272
CVE Name CVE-2015-3273
CVE Name CVE-2015-3274
CVE Name CVE-2015-3275
Message http://seclists.org/oss-sec/2015/q3/94
URL https://docs.moodle.org/dev/Moodle_2.7.9_release_notes
URL https://docs.moodle.org/dev/Moodle_2.8.7_release_notes
URL https://docs.moodle.org/dev/Moodle_2.9.1_release_notes