PT-2026-4784 · Forma Lms · Forma Lms

Hemant Patidar

·

Published

2026-01-26

·

Updated

2026-01-26

·

CVE-2020-36960

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Forma LMS version 2.3
Description A stored cross-site scripting issue exists that allows attackers to inject malicious scripts into the user profile first and last name fields. This enables the execution of arbitrary JavaScript when other users view the affected profile.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-36960

Affected Products

Forma Lms