CVE-2023-4973
Academy LMS GET Parameter filter cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] leads to cross site scripting. The attack can be launched remotely. The identifier VDB-239749 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Se encontró una vulnerabilidad en Academy LMS 6.2 en Windows. Ha sido declarado problemático. Una función desconocida del archivo /academy/tutor/filter del componente GET Parameter Handler es afectada por esta vulnerabilidad. La manipulación del argumento palabra_buscada/tipo_clase_tución_buscada[]/tipo_precio_buscado[]/duración_buscada[] conduce a cross site scripting. El ataque se puede lanzar de forma remota. A esta vulnerabilidad se le asignó el identificador VDB-239749. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera.
In Academy LMS 6.2 für Windows wurde eine problematische Schwachstelle ausgemacht. Hierbei betrifft es unbekannten Programmcode der Datei /academy/tutor/filter der Komponente GET Parameter Handler. Durch Manipulation des Arguments searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk.
Academy LMS version 6.2 suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-09-14 CVE Reserved
- 2023-09-15 CVE Published
- 2023-09-15 First Exploit
- 2024-08-02 CVE Updated
- 2025-01-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/174680 | 2023-09-15 | |
http://packetstormsecurity.com/files/174680/Academy-LMS-6.2-Cross-Site-Scripting.html | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Creativeitem Search vendor "Creativeitem" | Academy Lms Search vendor "Creativeitem" for product "Academy Lms" | 6.2 Search vendor "Creativeitem" for product "Academy Lms" and version "6.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|