com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-02-20T21:47:08.027Z
Updated: 2024-08-01T23:59:32.684Z
Reserved: 2024-02-14T17:40:03.688Z
Link: CVE-2024-26140
Vulnrichment
Updated: 2024-07-05T15:20:40.475Z
NVD
Status : Awaiting Analysis
Published: 2024-02-20T22:15:08.950
Modified: 2024-02-22T19:07:37.840
Link: CVE-2024-26140
Redhat
No data.