Vulnerabilities > Fortunescripts > Lynda Clone

DATE CVE VULNERABILITY TITLE RISK
2017-12-27 CVE-2017-17904 Cross-site Scripting vulnerability in Fortunescripts Lynda Clone 1.0
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.
3.5
2017-12-27 CVE-2017-17903 Cross-Site Request Forgery (CSRF) vulnerability in Fortunescripts Lynda Clone 1.0
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
6.8
2017-12-18 CVE-2017-17643 SQL Injection vulnerability in Fortunescripts Lynda Clone 1.0
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
network
low complexity
fortunescripts CWE-89
7.5