CVE-2024-41572

Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or execute actions such as injecting malicious scripts or redirecting users to malicious sites.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:lang-learn-guy:learning_with_texts:2.0.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-21 19:15

Updated : 2025-03-18 19:15


NVD link : CVE-2024-41572

Mitre link : CVE-2024-41572

CVE.ORG link : CVE-2024-41572


JSON object : View

Products Affected

lang-learn-guy

  • learning_with_texts
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')