CyberRota Analysis
AI-GeneratedThe H5P module `h5p-nodejs-library` is vulnerable to a stored cross-site scripting (XSS) flaw, allowing attackers to upload H5P content containing malicious JavaScript. When other users access this content, the injected script executes in their browsers, potentially compromising their sessions or data. Organizations utilizing this library, particularly those managing user-generated content, should prioritize addressing this vulnerability to safeguard their users.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.