SCHUTZWERK-SA-2024-006: Stored Cross-Site Scripting via text fields in H5P module (h5p-nodejs-library) of Lumi Education
Stored XSS in Lumi Education h5p-nodejs-library before 9.3.3 runs injected script in viewers' browsers.
SCHUTZWERK reported a stored cross-site scripting flaw, SCHUTZWERK-SA-2024-006, in Lumi Education's h5p-nodejs-library in all versions before 9.3.3. Authenticated users can place malicious JavaScript in text fields. That script executes in other users' browsers when they view the affected H5P content. No CVE or in-the-wild exploitation is mentioned.
- Affects h5p-nodejs-library versions before 9.3.3.
- JavaScript injected in text fields runs when H5P content is viewed.
- Tracked as SCHUTZWERK-SA-2024-006; no CVE is listed.
Posted by David Brown via Fulldisclosure on Sep 26 A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module h5p-nodejs-library by Lumi Education UG in versions prior to 9.3.3. The vulnerability allows users to inject malicious JavaScript code in text fields. This code is then executed in victims' browsers when viewing the affected H5P content. Metadata ======== - Affected product: h5p-nodejs-library - Affected version: All versions prior to 9.3.3 - Vendor:...
This source does not provide full text. Read it at seclists.org.