SCHUTZWERK-SA-2024-006: Stored Cross-Site Scripting via text fields in H5P module (h5p-nodejs-library) of Lumi Education
Stored XSS in Lumi Education h5p-nodejs-library before 9.3.3 runs injected script in viewers' browsers.
SCHUTZWERK reported a stored cross-site scripting flaw, SCHUTZWERK-SA-2024-006, in Lumi Education's h5p-nodejs-library in all versions before 9.3.3. Authenticated users can place malicious JavaScript in text fields. That script executes in other users' browsers when they view the affected H5P content. No CVE or in-the-wild exploitation is mentioned.
34