com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/yetanalytics/lrs/security/advisories/GHSA-7rw2-3hhp-rc46 | vendor advisory |
https://github.com/yetanalytics/lrs/commit/d7f4883bc2252337d25e8bba2c7f9d172f5b0621 | patch |
https://clojars.org/com.yetanalytics/lrs/versions/1.2.17 | product release notes |
https://github.com/yetanalytics/lrs/releases/tag/v1.2.17 | release notes |
https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5 | release notes |