First published: Mon Sep 26 2022(Updated: )
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Creativeitem Academy LMS | <5.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38553 is a reflected cross-site scripting (XSS) vulnerability in Academy Learning Management System before v5.9.1.
CVE-2022-38553 has a severity score of 6.1 (Medium).
Academy Learning Management System versions up to exclusive v5.9.1 are affected by CVE-2022-38553.
Update Academy Learning Management System to version 5.9.1 or later to fix CVE-2022-38553.
The CWE ID for CVE-2022-38553 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).