Логотип exploitDog
bind:CVE-2024-41572
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-41572

Количество 2

Количество 2

nvd логотип

CVE-2024-41572

больше 1 года назад

Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or execute actions such as injecting malicious scripts or redirecting users to malicious sites.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-pgqc-fvj2-w9mh

больше 1 года назад

Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-41572

Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or execute actions such as injecting malicious scripts or redirecting users to malicious sites.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-pgqc-fvj2-w9mh

Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization.

CVSS3: 6.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу