A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could exploit the 'localidad' parameter to inject a custom JavaScript payload and partially take over another user's browser session, due to the lack of proper sanitisation of the 'localidad' field on the /users/editmy page.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58600 | A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could exploit the 'localidad' parameter to inject a custom JavaScript payload and partially take over another user's browser session, due to the lack of proper sanitisation of the 'localidad' field on the /users/editmy page. |
Fixes
Solution
The vulnerability has been fixed in Alumne LMS version 4.0.0.1.44.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-02T08:28:21.868Z
Reserved: 2023-11-28T09:08:22.679Z
Link: CVE-2023-6359
No data.
Status : Modified
Published: 2023-11-28T12:15:07.647
Modified: 2024-11-21T08:43:42.053
Link: CVE-2023-6359
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD