CVE-2019-12834: HT2LABS Learning Locker

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.

Affected products

  • HT2LABS Learning Locker: version 3.15.1 only

Published 2019-07-16. Last modified 2026-06-17.