"value":"Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the \u201cback_url\u201d parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user\u00b4s cookies in order to log in to the application."
"value":"Forma LMS versi\u00f3n 3.1.0 y anteriores se ven afectados por una vulnerabilidad de Cross-Site Scripting, que podr\u00eda permitir a un atacante remoto inyectar c\u00f3digo javascript en el par\u00e1metro \u201cback_url\u201d en la funci\u00f3n appLms/index.php?modname=faq&op=play. La explotaci\u00f3n de esta vulnerabilidad podr\u00eda permitir a un atacante robar las cookies del usuario para iniciar sesi\u00f3n en la aplicaci\u00f3n.\n"