CVE-2022-47130
https://notcve.org/view.php?id=CVE-2022-47130
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page. • https://portswigger.net/web-security/csrf https://www.linkedin.com/in/xvinicius https://xpsec.co/blog/academy-lms-5-10-coupon-csrf • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-47131
https://notcve.org/view.php?id=CVE-2022-47131
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page. • https://blog.hackingforce.com.br/en/xss https://portswigger.net/web-security/csrf https://portswigger.net/web-security/csrf/xss-vs-csrf https://www.linkedin.com/in/xvinicius https://xpsec.co/blog/academy-lms-5-10-add-page-csrf-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-47132
https://notcve.org/view.php?id=CVE-2022-47132
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. • https://portswigger.net/web-security/csrf https://www.linkedin.com/in/xvinicius https://xpsec.co/blog/academy-lms-5-10-add-admin-csrf • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-29380
https://notcve.org/view.php?id=CVE-2022-29380
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel. Se ha detectado que Academy-LMS versión v4.3, contiene una vulnerabilidad de tipo cross-site scripting (XSS) almacenada en el panel SEO • https://www.exploit-db.com/exploits/49298 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •