CVE-2020-36998 - forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting
CVE ID : CVE-2020-36998
Published : Jan. 30, 2026, 5:16 p.m. | 1 hour, 43 minutes ago
Description : Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without proper input sanitization.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 30, 2026, 5:16 p.m. | 1 hour, 43 minutes ago
Description : Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without proper input sanitization.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...