PT-2022-19569 · Unknown · Academy Lms
Published
2022-05-25
·
Updated
2022-06-02
·
CVE-2022-29380
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Academy-LMS version 4.3
Description
A stored cross-site scripting (XSS) issue was found in the SEO panel of Academy-LMS. This type of issue allows attackers to inject malicious scripts into content, which are then stored on the server and executed by the browser when other users access the affected page.
Recommendations
For Academy-LMS version 4.3, update to a version that includes a fix for the stored cross-site scripting vulnerability in the SEO panel. As a temporary workaround, consider restricting access to the SEO panel to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Academy Lms