CourseMill Learning Management System CVE-2013-3604 Multiple HTML Injection Vulnerabilities
BID:61435
Info
CourseMill Learning Management System CVE-2013-3604 Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 61435 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3604 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2013 12:00AM |
| Updated: | Aug 30 2013 12:00AM |
| Credit: | Mike Czumak |
| Vulnerable: |
Trivantis CourseMill Learning Management System 6.8 Trivantis CourseMill Learning Management System 6.6 |
| Not Vulnerable: | |
Discussion
CourseMill Learning Management System CVE-2013-3604 Multiple HTML Injection Vulnerabilities
CourseMill Learning Management System is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied inputs.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and control how the site is rendered to the user; other attacks are also possible.
CourseMill Learning Management System 6.6 and 6.8 are vulnerable; other versions may also be affected.
CourseMill Learning Management System is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied inputs.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and control how the site is rendered to the user; other attacks are also possible.
CourseMill Learning Management System 6.6 and 6.8 are vulnerable; other versions may also be affected.