CVE-2022-41679
31.10.2022, 20:15
Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the back_url parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the users cookies in order to log in to the application.
Vendor | Product | Version |
---|---|---|
formalms | formalms | 𝑥 < 3.2.1 |
𝑥
= Vulnerable software versions