Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Very Low

CVE-2019-5111

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_cat was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.
Attacker Value
Very Low

CVE-2019-5112

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_status was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.
Attacker Value
Unknown

CVE-2023-46693

Disclosure Date: December 07, 2023 (last updated December 12, 2023)
Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters.
Attacker Value
Unknown

CVE-2022-41681

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the SCORM importer feature. The exploitation of this vulnerability could lead to a remote code injection.
Attacker Value
Unknown

CVE-2022-41679

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user´s cookies in order to log in to the application.
Attacker Value
Unknown

CVE-2022-42923

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'id' parameter in the 'appCore/index.php?r=adm/mediagallery/delete' function in order to dump the entire database or delete all contents from the 'core_user_file' table.
Attacker Value
Unknown

CVE-2022-42924

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'dyn_filter' parameter in the 'appLms/ajax.adm_server.php?r=widget/userselector/getusertabledata' function in order to dump the entire database.
Attacker Value
Unknown

CVE-2022-42925

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the plugin upload component. The exploitation of this vulnerability could lead to a remote code injection.
Attacker Value
Unknown

CVE-2022-41680

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'search[value] parameter in the appLms/ajax.server.php?r=mycertificate/getMyCertificates' function in order to dump the entire database.
Attacker Value
Unknown

CVE-2022-27104

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.