PT-2013-5740 · Trivantis · Coursemill Learning Management System

Publicado

2013-09-06

·

Atualizado

2013-09-06

·

CVE-2013-5706

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Coursemill Learning Management System (LMS) version 6.8
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via vectors related to error messages and specifically through crafted event attributes or the use of > (greater than) characters that are optional within a browser's HTML implementation.
Recommendations For Coursemill Learning Management System (LMS) version 6.8, update to a version that includes a fix for these XSS vulnerabilities. As a temporary workaround, consider restricting user input to prevent the injection of arbitrary web script or HTML, especially in areas related to error messages and event attributes.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-5706

Produtos afetados

Coursemill Learning Management System