Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ltgplc Subscribe
Filtered by product Rustici Software Scorm Engine
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2035 1 Ltgplc 1 Rustici Software Scorm Engine 2022-06-15 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an attacker to craft malicious urls which can trigger a reflected XSS payload in the context of a victim's browser.