SCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
Stored XSS in Lumi Education h5p-nodejs-library through 10.0.4 lets uploaded H5P content run JavaScript.
SCHUTZWERK advisory SA-2024-007 describes stored cross-site scripting in Lumi Education's h5p-nodejs-library, affecting all versions up to and including 10.0.4. The library accepts H5P uploads that can contain malicious JavaScript, which then runs in the browsers of other users who open that content. The visible disclosure does not list a CVE or say the flaw is being exploited.
- Stored XSS via H5P file upload in h5p-nodejs-library.
- All versions through 10.0.4 are affected.
- Malicious JavaScript runs for other users viewing the content.
- Published as SCHUTZWERK-SA-2024-007 on Full Disclosure.
Posted by David Brown via Fulldisclosure on Sep 22 A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module h5p-nodejs-library by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content. Metadata ======== - Affected product: h5p-nodejs-library - Affected version: All versions up to and...
This source does not provide full text. Read it at seclists.org.