Formalms

Formalms

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 13.24%
  • Veröffentlicht 10.11.2021 12:15:16
  • Zuletzt bearbeitet 21.11.2024 06:28:43

An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 08.10.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:20:18

forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to change the admin email address in order to accomplish an account takeover.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 03.12.2019 22:15:15
  • Zuletzt bearbeitet 21.11.2024 04:44:22

Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_status was confirmed to suffer from SQL injections and could be exploited by authenticated attackers....

Exploit
  • EPSS 0.49%
  • Veröffentlicht 03.12.2019 22:15:15
  • Zuletzt bearbeitet 21.11.2024 04:44:22

Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_cat was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 03.12.2019 22:15:15
  • Zuletzt bearbeitet 21.11.2024 04:44:22

Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger t...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 03.12.2019 22:15:14
  • Zuletzt bearbeitet 21.11.2024 04:44:22

Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger ...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 06.11.2014 15:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in Forma Lms before 1.2.1 p01 allow remote attackers to inject arbitrary web script or HTML via the (1) id_custom parameter in an amanmenu request or (2) id_game parameter in an alms/games/edit requ...