CVE-2022-47132: CSRF
Published Feb 3, 2023
·Updated
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
Affected Software
1 affected component
Creativeitem Academy LMS<5.10
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-47132.
2
What is the severity of CVE-2022-47132?
The severity of CVE-2022-47132 is high with a CVSS score of 8.8.
3
How does the vulnerability in Academy LMS before v5.10 impact users?
The vulnerability allows attackers to arbitrarily add Administrator users.
4
How can I fix the vulnerability in Academy LMS before v5.10?
To fix the vulnerability, update to Academy LMS version 5.10 or higher.
5
Is there any additional information available on this vulnerability?
Yes, you can find additional information on this vulnerability at the following references: [https://portswigger.net/web-security/csrf](https://portswigger.net/web-security/csrf), [https://www.linkedin.com/in/xvinicius/](https://www.linkedin.com/in/xvinicius/), [https://xpsec.co/blog/academy-lms-5-10-add-admin-csrf](https://xpsec.co/blog/academy-lms-5-10-add-admin-csrf).