CVE-2022-47130: CSRF
Published Feb 3, 2023
·Updated
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.
Affected Software
1 affected component
Creativeitem Academy LMS<5.10
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-47130?
CVE-2022-47130 is a Cross-Site Request Forgery (CSRF) vulnerability in Academy LMS before v5.10.
2
What is the severity of CVE-2022-47130?
CVE-2022-47130 has a severity rating of medium (4.3).
3
How can an attacker exploit CVE-2022-47130?
An attacker with administrative privileges can exploit CVE-2022-47130 by interacting on the CSRF page to arbitrarily create a discount coupon.
4
Which version of Academy LMS is affected by CVE-2022-47130?
Academy LMS versions up to and excluding v5.10 are affected by CVE-2022-47130.
5
Is there a fix for CVE-2022-47130?
Upgrading Academy LMS to version 5.10 or later will fix CVE-2022-47130.