PT-2022-19569 · Unknown · Academy Lms

Published

2022-05-25

·

Updated

2022-06-02

·

CVE-2022-29380

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Academy-LMS version 4.3
Description A stored cross-site scripting (XSS) issue was found in the SEO panel of Academy-LMS. This type of issue allows attackers to inject malicious scripts into content, which are then stored on the server and executed by the browser when other users access the affected page.
Recommendations For Academy-LMS version 4.3, update to a version that includes a fix for the stored cross-site scripting vulnerability in the SEO panel. As a temporary workaround, consider restricting access to the SEO panel to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29380

Affected Products

Academy Lms