NA

CVE-2022-41679

Published: 31/10/2022 Updated: 01/11/2022
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Forma LMS version 3.1.0 and previous versions are affected by an Cross-Site scripting vulnerability, that could allow a remote malicious user to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an malicious user to steal the user´s cookies in order to log in to the application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

formalms formalms