vendor:
Chamilo LMS
by:
sirpedrotavares
5.4
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Chamilo LMS
Affected Version From: Chamilo-lms-1.11.x
Affected Version To: Chamilo-lms-1.11.x
Patch Exists: YES
Related CWE: CVE-2021-37391
CPE: Chamilo-lms-1.11.x
Platforms Tested:
2021
Chamilo LMS 1.11.14 – Account Takeover
A user without privileges in Chamilo LMS 1.11.x can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
Mitigation:
Update the Chamilo to the latest version.