Description
In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4414 | In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:32:55.404Z
Reserved: 2019-06-15T00:00:00.000Z
Link: CVE-2019-12834
No data.
Status : Modified
Published: 2019-07-16T18:15:12.397
Modified: 2024-11-21T04:23:40.807
Link: CVE-2019-12834
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD