CVE-2020-36960 Details
Description
Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.
A stored cross-site scripting vulnerability has been identified in Forma LMS version 2.3. This issue allows attackers to inject malicious scripts into the first and last name fields of user profiles. When the profile is viewed by other users, the injected scripts are executed, potentially leading to the execution of arbitrary JavaScript. For example, a script could be crafted to alert the user's cookies.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 26, 2026CISA-ADP
Assessed Jan 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/49197 | [email protected] | Exploit |
| https://www.formalms.org/ | [email protected] | Permission RequiredVendor |
| https://www.vulncheck.com/advisories/forma-lms-first-last-name-stored-cross-site-scripting | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Forma LMS | <= 2.3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 26, 2026 | New CVE Received | [email protected] |
Volerion