CVE-2024-56939

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 12, 2025
Updated: Feb 24, 2025
CWE ID 79

Summary

CVE-2024-56939 is a newly disclosed stored cross-site scripting (XSS) vulnerability affecting LearnDash version 6.7.1. Hackers can exploit this issue by injecting malicious scripts into comment fields that are later stored in the database. The vulnerability lies within the 'ld-comment-body' class, enabling attackers to execute code in the context of other users. Successful exploitation could lead to account takeover, data theft, or unauthorized system access. Users are advised to update to the latest version of LearnDash as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share