Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or execute actions such as injecting malicious scripts or redirecting users to malicious sites.
References
Link | Resource |
---|---|
https://medium.com/%40ChadSecurity/cve-2024-41572-68397fae354b | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-08-21 19:15
Updated : 2025-03-18 19:15
NVD link : CVE-2024-41572
Mitre link : CVE-2024-41572
CVE.ORG link : CVE-2024-41572
JSON object : View
Products Affected
lang-learn-guy
- learning_with_texts
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')