PT-2025-3696 · Viwis Lms · Viwis Lms

Ralph Meier

·

Published

2025-01-08

·

Updated

2025-01-08

·

CVE-2024-8002

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions VIWIS LMS version 9.11
Description A vulnerability has been found in the File Upload component of VIWIS LMS, affecting an unknown functionality. The manipulation of the filename argument leads to cross-site scripting. The attack can be launched remotely. Upgrading to version 9.12 is able to address this issue.
Recommendations For VIWIS LMS version 9.11, upgrade to version 9.12 to address the issue. As a temporary workaround, consider restricting the use of the File Upload component until the upgrade is applied.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-8002

Affected Products

Viwis Lms