Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POST Parameter in user-code-redemption.php, the ulgm_user_first POST Parameter in user-registration-form.php, the ulgm_user_last POST Parameter in user-registration-form.php, the ulgm_user_email POST Parameter in user-registration-form.php, the ulgm_code_registration POST Parameter in user-registration-form.php, the ulgm_terms_conditions POST Parameter in user-registration-form.php, the _ulgm_total_seats POST Parameter in frontend-uo_groups_buy_courses.php, the uncanny_group_signup_user_first POST Parameter in group-registration-form.php, the uncanny_group_signup_user_last POST Parameter in group-registration-form.php, the uncanny_group_signup_user_login POST Parameter in group-registration-form.php, the uncanny_group_signup_user_email POST Parameter in group-registration-form.php, the success-invited GET Parameter in frontend-uo_groups.php, the bulk-errors GET Parameter in frontend-uo_groups.php, or the message GET Parameter in frontend-uo_groups.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uncannyowl | Uncanny Groups For Learndash | < 3.7 |
Related Weaknesses (CWE)
References
- https://gist.github.com/michiiii/81d801f563138abe7da61e2d95342202Third Party Advisory
- https://www.uncannyowl.com/knowledge-base/uncanny-learndash-groups-changelog/Release NotesVendor Advisory
- https://gist.github.com/michiiii/81d801f563138abe7da61e2d95342202Third Party Advisory
- https://www.uncannyowl.com/knowledge-base/uncanny-learndash-groups-changelog/Release NotesVendor Advisory
FAQ
What is CVE-2020-35650?
CVE-2020-35650 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POS...
How severe is CVE-2020-35650?
CVE-2020-35650 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35650?
Check the references section above for vendor advisories and patch information. Affected products include: Uncannyowl Uncanny Groups For Learndash.