What the vulnerability does
01Description
In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.
CVSS base score
CVSS vector
CVSS:3.0/AC:L/AV:N/A:L/C:L/I:L/PR:N/S:U/UI:N
What the vulnerability does
In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.
Key dates
External resources