First published: Wed Dec 23 2020(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POST Parameter in user-code-redemption.php, the ulgm_user_first POST Parameter in user-registration-form.php, the ulgm_user_last POST Parameter in user-registration-form.php, the ulgm_user_email POST Parameter in user-registration-form.php, the ulgm_code_registration POST Parameter in user-registration-form.php, the ulgm_terms_conditions POST Parameter in user-registration-form.php, the _ulgm_total_seats POST Parameter in frontend-uo_groups_buy_courses.php, the uncanny_group_signup_user_first POST Parameter in group-registration-form.php, the uncanny_group_signup_user_last POST Parameter in group-registration-form.php, the uncanny_group_signup_user_login POST Parameter in group-registration-form.php, the uncanny_group_signup_user_email POST Parameter in group-registration-form.php, the success-invited GET Parameter in frontend-uo_groups.php, the bulk-errors GET Parameter in frontend-uo_groups.php, or the message GET Parameter in frontend-uo_groups.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uncanny Owl Uncanny Groups For LearnDash | <3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35650 is a vulnerability that involves multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7.
The severity of CVE-2020-35650 is medium with a CVSS score of 6.1.
Authenticated remote attackers can exploit CVE-2020-35650 by injecting arbitrary JavaScript or HTML via the ulgm_code_redeem POST parameter in user-code-redemption.php or the ulgm_user_first POST parameter in user-registration-for.
The affected software of CVE-2020-35650 is Uncanny Groups for LearnDash before v3.7.
You can find more information about CVE-2020-35650 at the following references: [Link 1](https://gist.github.com/michiiii/81d801f563138abe7da61e2d95342202) and [Link 2](https://www.uncannyowl.com/knowledge-base/uncanny-learndash-groups-changelog/).