# Exploit Title: forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting # Date: 2020-05-15 # Exploit Author: Daniel Ortiz # Vendor Homepage: https://sourceforge.net/projects/forma/ # Software link: https://sourceforge.net/projects/forma/files/latest/download # Tested on: XAMPP for Linux 64bit 5.6.40-0 ## 1 -Course Module - Vulnerable parameter: course_code, course_name, course_box_descr, course_descr - Payload: - Details: There is no control or security mechanism on this field. Specials characters are not encoded or filtered. - Privileges: It requires admin. - Location: Admin Area > E-learning > Courses > Courses > Edit Course - Endopoint: /formalms/appCore/index.php?r=alms/course/modcourse ## 1 -Profile Module - Vulnerable parameter: Email - Payload: