Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users. | |
| Title | Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-26T20:55:45.410Z
Reserved: 2026-01-26T14:18:25.795Z
Link: CVE-2020-36960
Updated: 2026-01-26T20:55:41.715Z
Status : Received
Published: 2026-01-26T18:16:27.020
Modified: 2026-01-26T18:16:27.020
Link: CVE-2020-36960
No data.
OpenCVE Enrichment
No data.