PT-2024-16908 · Unknown · Hi E-Learning Learning Management System

Published

2024-12-06

·

Updated

2026-06-02

·

CVE-2024-11321

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hi e-learning Learning Management System (LMS) versions prior to 06.12.2024
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for Reflected XSS.
Recommendations For versions prior to 06.12.2024, update to a version released after 06.12.2024 to resolve the issue. As a temporary workaround, consider restricting user input in web page generation to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-11321

Affected Products

Hi E-Learning Learning Management System