PT-2025-40820 · Codecanyon · Ui-Lib+1

Jaredloo

·

Published

2025-10-05

·

Updated

2025-10-06

·

CVE-2025-11304

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodeCanyon/ui-lib Mentor LMS versions up to 1.1.1
Description A flaw exists in the component API of CodeCanyon/ui-lib Mentor LMS. This issue can lead to a permissive cross-domain policy with untrusted domains, allowing for remote attacks. The exploit has been published. The vendor was contacted but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2025-11304

Affected Products

Mentor Lms
Ui-Lib