CVE-2020-36960: Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting
Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36960?
CVE-2020-36960 is classified as a medium severity stored cross-site scripting vulnerability.
How do I fix CVE-2020-36960?
To fix CVE-2020-36960, ensure proper sanitization and validation of input in user profile first and last name fields.
What are the potential impacts of CVE-2020-36960?
The potential impacts of CVE-2020-36960 include the injection of malicious scripts that can compromise user data and session information.
Which versions of Forma LMS are affected by CVE-2020-36960?
CVE-2020-36960 affects Forma LMS version 2.3.
How can attackers exploit CVE-2020-36960?
Attackers can exploit CVE-2020-36960 by injecting harmful scripts into the 'First & Last Name' fields, leading to unauthorized actions performed on behalf of users.