S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-38553 Scanner

CVE-2022-38553 scanner - Cross-Site Scripting (XSS) vulnerability in Academy Learning Management System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-38553
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Academy Learning Management System is a digital platform used for educational purposes. It is designed to provide users with a user-friendly, interactive, and convenient way to access and manage educational content. With its advanced features and functionalities, the Academy Learning Management System is widely used by educational institutions and organizations across the globe.

However, the Academy Learning Management System was recently found to contain a critical vulnerability, CVE-2022-38553. This vulnerability is referred to as a reflected cross-site scripting (XSS) vulnerability, which means that it allows attackers to inject malicious code into the search parameter of the platform. This vulnerability affects the system's search function, allowing attackers to execute arbitrary code on the system and access sensitive information.

When exploited, the CVE-2022-38553 vulnerability can lead to significant security risks and consequences. Attackers can use this vulnerability to obtain sensitive information such as usernames, passwords, and other confidential data. They can also launch a range of other attacks, including phishing, malware injection, and denial-of-service attacks.

In conclusion, the CVE-2022-38553 vulnerability in the Academy Learning Management System highlights the critical importance of taking proactive measures to safeguard digital assets against cyber threats. Thanks to the pro features of the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets and take appropriate action to ensure maximum security and protection.

 

REFERENCES

Solution Advice

As a precautionary measure, users of the Academy Learning Management System should take appropriate steps to protect their digital assets. Some of the precautions that can be taken include:

  • Keeping the software up-to-date and installing patches promptly
  • Implementing strong passwords and two-factor authentication
  • Running regular security scans and audits on the system
  • Limiting access to the system to authorized personnel only
  • Establishing clear security policies and educating users on best practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-38553 scanner - Cross-Site Scripting (XSS) vulnerability in Academy Learning Management System | S4E