CVE-2022-29380
MEDIUMAcademy-LMS 4.3 - Stored Cross-Site Scripting in SEO Panel
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-29380. PoCs published by Vinicius Alves, OpenXP-Research.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Academy-LMS 4.3. The payload is injected via the course manager's SEO menu and triggers when the course page is accessed.
Description
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in Academy-LMS 4.3. The payload is injected via the course manager's SEO menu and triggers when the course page is accessed.
This repository contains a README describing CVE-2022-29380, a Cross-Site Scripting (XSS) vulnerability in Academy LMS versions up to 4.3. The README provides basic details such as the CVE ID, affected software, vulnerability type, and references.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N