PT-2024-21297 · Unknown+1 · Com.Yetanalytics/Lrs+1

Cliffcasey

·

Published

2024-02-20

·

Updated

2025-02-05

·

CVE-2024-26140

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions com.yetanalytics/lrs versions prior to 1.2.17 SQL LRS versions prior to 0.7.5
Description A maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. No known workarounds exist.
Recommendations For com.yetanalytics/lrs versions prior to 1.2.17, update to version 1.2.17 to resolve the issue. For SQL LRS versions prior to 0.7.5, update to version 0.7.5 to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-26140
GHSA-7RW2-3HHP-RC46

Affected Products

Sql Lrs
Com.Yetanalytics/Lrs