4 results (0.004 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page. • https://portswigger.net/web-security/csrf https://www.linkedin.com/in/xvinicius https://xpsec.co/blog/academy-lms-5-10-coupon-csrf • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page. • https://blog.hackingforce.com.br/en/xss https://portswigger.net/web-security/csrf https://portswigger.net/web-security/csrf/xss-vs-csrf https://www.linkedin.com/in/xvinicius https://xpsec.co/blog/academy-lms-5-10-add-page-csrf-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. • https://portswigger.net/web-security/csrf https://www.linkedin.com/in/xvinicius https://xpsec.co/blog/academy-lms-5-10-add-admin-csrf • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel. Se ha detectado que Academy-LMS versión v4.3, contiene una vulnerabilidad de tipo cross-site scripting (XSS) almacenada en el panel SEO • https://www.exploit-db.com/exploits/49298 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •