Junglewise Threat Intelligence

CVE-2025-46102: Beakon Learning Management System XSS in SCORM loader

CVE-2025-46102 · Severity: medium · CVSS 5.4 · Published 2025-07-17

Executive brief

Beakon Learning Management System, a platform used for corporate training and compliance, contains a security flaw in its SCORM content loader. An attacker could use this vulnerability to execute malicious scripts in a user's browser, potentially leading to the theft of login session information or other sensitive data. This could compromise the accounts of employees or contractors using the training system.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in Beakon Learning Management System (LMS) version 5.4.3 within the SCORM (Sharable Content Object Reference Model) loader component. The vulnerability is located in the 'loader.html' file, where the 'url' parameter is improperly neutralized before being rendered in the page. A remote attacker with low privileges can craft a malicious URL (e.g., using the 'javascript:' pseudo-protocol) and trick a victim into clicking it. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, enabling the theft of session cookies or other sensitive data.

Affected products

  • Beakon Software Learning Management System SCORM loader 5.4.3

Timeline

  • 2025-07-17: advisory
  • 2025-07-17: disclosed

References