LAMS (Learning Activity Management System) is an educational learning-management platform with a narrowly scoped vulnerability footprint centered on its core product. The observed weakness class reflects typical web-application input-handling exposure, with cross-site scripting vulnerabilities arising from insufficient neutralization of user-supplied content in page generation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lamsfoundation over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12090MEDIUM There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized | Jun 11, 2018 | 6.1 | 30 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lamsfoundation.
Media articles that mention a CVE ID that affects a product developed by Lamsfoundation — matched by CVE ID, not by vendor name.