First published: Wed May 25 2022(Updated: )
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Creativeitem Academy LMS | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-29380 is medium with a CVSS score of 4.8.
CVE-2022-29380 is a stored cross-site scripting (XSS) vulnerability.
The stored cross-site scripting (XSS) vulnerability affects the SEO panel of Academy-LMS v4.3.
To fix CVE-2022-29380 in Academy-LMS v4.3, update to a version that is not affected by the vulnerability.
Yes, there is a known exploit for CVE-2022-29380 which can be found at https://www.exploit-db.com/exploits/49298.