Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or execute actions such as injecting malicious scripts or redirecting users to malicious sites.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 06 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lang-learn-guy
Lang-learn-guy learning With Texts |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:lang-learn-guy:learning_with_texts:2.0.3:*:*:*:*:*:*:* | |
Vendors & Products |
Lang-learn-guy
Lang-learn-guy learning With Texts |
|
Metrics |
cvssV3_1
|
Thu, 22 Aug 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. | Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or execute actions such as injecting malicious scripts or redirecting users to malicious sites. |
Thu, 22 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 21 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-18T18:15:09.489Z
Reserved: 2024-07-18T00:00:00.000Z
Link: CVE-2024-41572

Updated: 2024-08-22T13:41:18.439Z

Status : Modified
Published: 2024-08-21T19:15:13.380
Modified: 2025-03-18T19:15:43.633
Link: CVE-2024-41572

No data.