PT-2025-3696 · Viwis Lms · Viwis Lms
Ralph Meier
·
Published
2025-01-08
·
Updated
2025-01-08
·
CVE-2024-8002
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
VIWIS LMS version 9.11
Description
A vulnerability has been found in the File Upload component of VIWIS LMS, affecting an unknown functionality. The manipulation of the
filename argument leads to cross-site scripting. The attack can be launched remotely. Upgrading to version 9.12 is able to address this issue.Recommendations
For VIWIS LMS version 9.11, upgrade to version 9.12 to address the issue. As a temporary workaround, consider restricting the use of the File Upload component until the upgrade is applied.
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Viwis Lms