CVE-2020-36960

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-26 18:16

Updated : 2026-01-27 14:59


NVD link : CVE-2020-36960

Mitre link : CVE-2020-36960

CVE.ORG link : CVE-2020-36960


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')