
CVE-2022-47132
Academy LMS <= 5.10 CSRF
exploitationpenetration-testingsocial-engineering+2

Academy LMS <= 5.10 CSRF
CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…