Two stored XSS flaws in Lumi H5P library
SCHUTZWERK disclosed two stored XSS bugs in Lumi Education h5p-nodejs-library: text-field injection before 9.3.3 and H5P upload XSS through 10.0.4.
SCHUTZWERK published two stored cross-site scripting advisories for Lumi Education's h5p-nodejs-library. SCHUTZWERK-SA-2024-006 affects all versions before 9.3.3: authenticated users can place malicious JavaScript in text fields, and that script runs in other users' browsers when they view the content. SCHUTZWERK-SA-2024-007 affects all versions up to and including 10.0.4 and lets uploaded H5P packages carry JavaScript that runs for viewers of that content. The Full Disclosure posts are dated 2026-09-22 for SA-2024-007 and 2026-09-27 for SA-2024-006. Neither report lists a CVE or mentions in-the-wild exploitation. The differing version ranges reflect two separate issues, not conflicting descriptions of one bug.
- SCHUTZWERK-SA-2024-006 is stored XSS via text fields in Lumi Education h5p-nodejs-library versions before 9.3.3.
- Authenticated users can inject JavaScript in those text fields; it runs in other users' browsers when they view the H5P content.
- SCHUTZWERK-SA-2024-007 is stored XSS via H5P file upload in the same library, affecting all versions through 10.0.4.
- Uploaded H5P content can contain malicious JavaScript that runs for other users who open it.
- Neither Full Disclosure post lists a CVE or says either flaw is being exploited.
- The SA-2024-007 post is dated 2026-09-22 and the SA-2024-006 post is dated 2026-09-27.
Coverage timelineoldest first · each row is one article
- · 4d agoSCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
Full Disclosure· 42
Stored XSS in Lumi Education h5p-nodejs-library through 10.0.4 lets uploaded H5P content run JavaScript.
- · 3h agoSCHUTZWERK-SA-2024-006: Stored Cross-Site Scripting via text fields in H5P module (h5p-nodejs-library) of Lumi Education
Full Disclosure· 34
Stored XSS in Lumi Education h5p-nodejs-library before 9.3.3 runs injected script in viewers' browsers.