First published: Fri Dec 15 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeum Tutor LMS | <=2.2.4 |
Update to 2.3.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49829 has a high severity level due to its potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2023-49829, update Themeum Tutor LMS to the latest version, ensuring it is beyond version 2.2.4.
CVE-2023-49829 affects users of Themeum Tutor LMS versions up to and including 2.2.4.
CVE-2023-49829 is classified as an improper neutralization of input vulnerability resulting in stored cross-site scripting (XSS).
Failing to mitigate CVE-2023-49829 could allow attackers to execute malicious scripts in users' browsers, compromising sensitive data.