Описание
com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.
Ссылки
- ProductRelease Notes
- Patch
- Release Notes
- Vendor Advisory
- Release Notes
- ProductRelease Notes
- Patch
- Release Notes
- Vendor Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.17 (исключая)Версия до 0.7.5 (исключая)
Одно из
cpe:2.3:a:yetanalytics:lrs:*:*:*:*:*:*:*:*
cpe:2.3:a:yetanalytics:sql_lrs:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00166
Низкий
4.6 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 4.6
github
почти 2 года назад
Cross-site Scripting Vulnerability in Statement Browser
EPSS
Процентиль: 38%
0.00166
Низкий
4.6 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79