Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-44864 | Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user´s cookies in order to log in to the application. |
Fri, 02 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-02T19:57:29.942Z
Reserved: 2022-09-28T00:00:00.000Z
Link: CVE-2022-41679
Updated: 2024-08-03T12:49:43.458Z
Status : Modified
Published: 2022-10-31T20:15:13.300
Modified: 2024-11-21T07:23:37.670
Link: CVE-2022-41679
No data.
OpenCVE Enrichment
No data.
EUVD