LMS by LifterLMS <= 3.35.0 - Stored Cross-Site Scripting via Import
2019-09-09 00:00
Jerome BruandetStrategic Overview
StatusPatched in 3.35.0
Affected PluginLifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
Affected Version
< 3.35.0CVSS9.8Critical
CVE
CVE-2019-15896Vulnerability Overview
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.
Technical Analysis
REMEDIATION: Update to version 3.35.0, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C