VYPR
Medium severity5.4NVD Advisory· Published Nov 28, 2023· Updated Jun 17, 2026

CVE-2023-6359

CVE-2023-6359

Description

A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could exploit the 'localidad' parameter to inject a custom JavaScript payload and partially take over another user's browser session, due to the lack of proper sanitisation of the 'localidad' field on the /users/editmy page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:grupoalumne:alumne_lms:4.0.0.1.08:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:grupoalumne:alumne_lms:4.0.0.1.08:*:*:*:*:*:*:*
    • (no CPE)range: 4.0.0.1.08
  • Range: = 4.0.0.1.08

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.