Description
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-49905 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page. |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 26 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-26T15:40:02.925Z
Reserved: 2022-12-12T00:00:00.000Z
Link: CVE-2022-47130
Updated: 2024-08-03T14:47:28.532Z
Status : Modified
Published: 2023-02-03T01:15:12.197
Modified: 2025-03-26T16:15:16.503
Link: CVE-2022-47130
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD