{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-30T15:27:10.393","vulnerabilities":[{"cve":{"id":"CVE-2024-26140","sourceIdentifier":"security-advisories@github.com","published":"2024-02-20T22:15:08.950","lastModified":"2025-02-05T22:34:32.020","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist."},{"lang":"es","value":"com.yetanalytics/lrs es la librería LRS principal de Yet Analytics. Antes de la versión 1.2.17 de la librería LRS y la versión 0.7.5 de SQL LRS, se podía utilizar una declaración xAPI creada con fines malintencionados para realizar una inyección de script u otras etiquetas en el navegador de declaraciones LRS. El problema se solucionó en la versión 1.2.17 de la librería LRS y en la versión 0.7.5 de SQL LRS. No existen workarounds conocidas."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yetanalytics:lrs:*:*:*:*:*:*:*:*","versionEndExcluding":"1.2.17","matchCriteriaId":"CA215B85-84E9-4032-A0B1-BEA4B6F27F5D"},{"vulnerable":true,"criteria":"cpe:2.3:a:yetanalytics:sql_lrs:*:*:*:*:*:*:*:*","versionEndExcluding":"0.7.5","matchCriteriaId":"AB697355-88AA-48FC-A35B-FCABBB7B16DA"}]}]}],"references":[{"url":"https://clojars.org/com.yetanalytics/lrs/versions/1.2.17","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/yetanalytics/lrs/commit/d7f4883bc2252337d25e8bba2c7f9d172f5b0621","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/yetanalytics/lrs/releases/tag/v1.2.17","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/yetanalytics/lrs/security/advisories/GHSA-7rw2-3hhp-rc46","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://clojars.org/com.yetanalytics/lrs/versions/1.2.17","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Release Notes"]},{"url":"https://github.com/yetanalytics/lrs/commit/d7f4883bc2252337d25e8bba2c7f9d172f5b0621","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/yetanalytics/lrs/releases/tag/v1.2.17","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/yetanalytics/lrs/security/advisories/GHSA-7rw2-3hhp-rc46","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]}]}}]}