Security Advisory
CVE-2015-5337
6.1
MEDIUM
Vulnerability Description
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.
Published Date
February 22, 2016
Official Source
NIST NVD Advisory