CVE-2021-24308: LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24308.
What is the severity of CVE-2021-24308?
The severity of CVE-2021-24308 is medium with a CVSS score of 5.4.
Which software versions are affected by CVE-2021-24308?
Software versions up to but excluding 4.21.1 of LifterLMS - Online Course, Membership & Learning Management System Plugin for WordPress are affected by CVE-2021-24308.
What is the CWE ID associated with CVE-2021-24308?
The CWE ID associated with CVE-2021-24308 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
How can I fix CVE-2021-24308?
To fix CVE-2021-24308, update LifterLMS - Online Course, Membership & Learning Management System Plugin for WordPress to version 4.21.1 or later.