漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cross-site scripting in Forma LMS version
Vulnerability Description
Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user´s cookies in order to log in to the application.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Forma Learning Management System 跨站脚本漏洞
Vulnerability Description
Forma Learning Management System(LMS)是一套学习管理系统(LMS)。 Forma Learning Management System 3.1.0 及之前版本存在安全漏洞,该漏洞源于允许远程攻击者在back_url参数上注入 JavaScript 代码,攻击者利用该漏洞可以窃取用户的 cookie 以登录应用程序。
CVSS Information
N/A
Vulnerability Type
N/A