Description
A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could exploit the 'localidad' parameter to inject a custom JavaScript payload and partially take over another user's browser session, due to the lack of proper sanitisation of the 'localidad' field on the /users/editmy page.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerability has been fixed in Alumne LMS version 4.0.0.1.44.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58600 | A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could exploit the 'localidad' parameter to inject a custom JavaScript payload and partially take over another user's browser session, due to the lack of proper sanitisation of the 'localidad' field on the /users/editmy page. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-02T08:28:21.868Z
Reserved: 2023-11-28T09:08:22.679Z
Link: CVE-2023-6359
No data.
Status : Modified
Published: 2023-11-28T12:15:07.647
Modified: 2026-06-17T06:50:36.423
Link: CVE-2023-6359
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD