Cross Site Scripting Vulnerability in VIWIS LMS by VIWIS
CVE-2024-8002
6.9MEDIUM
What is CVE-2024-8002?
A vulnerability exists in VIWIS LMS version 9.11 within the file upload functionality, where improper handling of the filename argument allows remote attackers to execute cross site scripting (XSS) attacks. This capability can lead to unauthorized actions on behalf of users accessing the affected application. It is strongly recommended to upgrade to version 9.12 to mitigate this risk.
Affected Version(s)
LMS 9.11