com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0562 | com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist. |
Github GHSA |
GHSA-7rw2-3hhp-rc46 | Cross-site Scripting Vulnerability in Statement Browser |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 05 Feb 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yetanalytics
Yetanalytics lrs Yetanalytics sql Lrs |
|
| CPEs | cpe:2.3:a:yetanalytics:lrs:*:*:*:*:*:*:*:* cpe:2.3:a:yetanalytics:sql_lrs:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Yetanalytics
Yetanalytics lrs Yetanalytics sql Lrs |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-01T23:59:32.684Z
Reserved: 2024-02-14T17:40:03.688Z
Link: CVE-2024-26140
Updated: 2024-07-05T15:20:40.475Z
Status : Analyzed
Published: 2024-02-20T22:15:08.950
Modified: 2025-02-05T22:34:32.020
Link: CVE-2024-26140
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA