Логотип exploitDog
bind:CVE-2020-36960
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-36960

Количество 2

Количество 2

nvd логотип

CVE-2020-36960

13 дней назад

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-h998-w3jj-3fwp

13 дней назад

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-36960

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CVSS3: 6.4
0%
Низкий
13 дней назад
github логотип
GHSA-h998-w3jj-3fwp

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CVSS3: 6.4
0%
Низкий
13 дней назад

Уязвимостей на страницу