CVE-2022-29380: XSS
Published May 25, 2022
·Updated
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
Affected Software
1 affected component
Creativeitem Academy LMS=4.3
Event History
May 25, 2022
CVE Published
via MITRE·01:14 PM
Data Sourced
via MITRE·01:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29380?
The severity of CVE-2022-29380 is medium with a CVSS score of 4.8.
2
What is the vulnerability type of CVE-2022-29380?
CVE-2022-29380 is a stored cross-site scripting (XSS) vulnerability.
3
How does the stored cross-site scripting (XSS) vulnerability affect Academy-LMS v4.3?
The stored cross-site scripting (XSS) vulnerability affects the SEO panel of Academy-LMS v4.3.
4
How can I fix CVE-2022-29380 in Academy-LMS v4.3?
To fix CVE-2022-29380 in Academy-LMS v4.3, update to a version that is not affected by the vulnerability.
5
Is there any known exploit for CVE-2022-29380?
Yes, there is a known exploit for CVE-2022-29380 which can be found at https://www.exploit-db.com/exploits/49298.