Show filters
60 Total Results
Displaying 31-40 of 60
Sort by:
Attacker Value
Unknown
CVE-2024-5588
Disclosure Date: June 02, 2024 (last updated February 12, 2025)
A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266839.
0
Attacker Value
Unknown
CVE-2024-5519
Disclosure Date: May 30, 2024 (last updated February 12, 2025)
A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-266590 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-40607
Disclosure Date: October 06, 2023 (last updated October 09, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions.
0
Attacker Value
Unknown
CVE-2023-36690
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
0
Attacker Value
Unknown
CVE-2023-1728
Disclosure Date: April 04, 2023 (last updated December 22, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection.This issue affects LMS: before 23.04.03.
0
Attacker Value
Unknown
CVE-2022-38553
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
0
Attacker Value
Unknown
CVE-2021-25029
Disclosure Date: February 07, 2022 (last updated February 23, 2025)
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2022-23437
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
0
Attacker Value
Unknown
CVE-2021-25200
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
0
Attacker Value
Unknown
CVE-2021-25201
Disclosure Date: July 23, 2021 (last updated February 23, 2025)
SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.
0