Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LAMS 跨站脚本漏洞
Vulnerability Description
LAMS是一套开源的学习活动管理系统。该系统用于设计、管理并提供在线协作学习活动。 LAMS 3.1之前版本中存在跨站脚本漏洞。远程攻击者可在密码更改过程中操纵未过滤的GET参数利用该漏洞注入任意的JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A