Vulnerability Description
Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user´s cookies in order to log in to the application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Formalms | Formalms | < 3.2.1 |
Related Weaknesses (CWE)
References
- https://www.incibe-cert.es/en/early-warning/security-advisories/multiple-vulneraPatchThird Party Advisory
- https://www.incibe-cert.es/en/early-warning/security-advisories/multiple-vulneraPatchThird Party Advisory
FAQ
What is CVE-2022-41679?
CVE-2022-41679 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?...
How severe is CVE-2022-41679?
CVE-2022-41679 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41679?
Check the references section above for vendor advisories and patch information. Affected products include: Formalms Formalms.