PT-2024-25762 · Rocketsoft · Rocket Lms

Sergio Medeiros

·

Published

2024-05-16

·

Updated

2024-07-10

·

CVE-2024-34241

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rocketsoft Rocket LMS version 1.9
Description A cross-site scripting (XSS) issue allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications, potentially compromising user sessions.
Recommendations For Rocketsoft Rocket LMS version 1.9, patch immediately and validate user input to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the admin web interface for creating new courses and course notifications until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-34241

Affected Products

Rocket Lms