Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting
Vulnerability Description
Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36960
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Hemant Patidar (HemantSolo)
Affected Vendor
Formalms
View all reports →