CVE-2024-41572 Information

Description

Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization.

Reference

https://drive.google.com/drive/folders/12NAfZ2VrMvJug1JVSzfz9PwCuttnlwzP https://medium.com/%40ChadSecurity/cve-2024-41572-68397fae354b

Share on: