Vulnerability CVE-2022-47130


Published: 2023-02-03

Description:
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.

 References:
https://portswigger.net/web-security/csrf
https://xpsec.co/blog/academy-lms-5-10-coupon-csrf
https://www.linkedin.com/in/xvinicius/

Copyright 2026, cxsecurity.com

 

Back to Top