CAMP-2026-0003
XSS via unescaped LRS response in admin reports
Componentlogstore_xapi
SeverityMEDIUM
Affected versions<5.0.3
Fixed in5.0.3
Published2026-07-21T20:29:50Z
Fix released2026-07-20
Details
The LRS response body and, in the historic report, the username were written into HTML table cells without escaping. A malicious or compromised LRS could execute script in the browser of a manager or administrator viewing the reports. Fixed in 5.0.3, which escapes both. Administrators should upgrade to 5.0.3 or later; sites pointing at an untrusted or shared LRS should treat this with elevated priority.