Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-42925
HistoryOct 31, 2022 - 8:15 p.m.

Code injection

2022-10-3120:15:00
PRIOn knowledge base
www.prio-n.com
4
forma lms
zip file upload
vulnerability
remote code injection

9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the plugin upload component. The exploitation of this vulnerability could lead to a remote code injection.

CPENameOperatorVersion
formalmslt3.2.1

9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

Related for PRION:CVE-2022-42925