XSS Vulnerability in Chamilo LMS Affects User Profile Management
CVE-2020-23126

6.1MEDIUM

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
3 November 2021

What is CVE-2020-23126?

Chamilo LMS version 1.11.10 is susceptible to a cross-site scripting (XSS) vulnerability in the personal profile edition form. This flaw allows an attacker to execute arbitrary scripts in the context of the user's session, affecting both the user and their social network friends. Users are encouraged to update to the latest version and apply necessary security measures to protect their information.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-23126 : XSS Vulnerability in Chamilo LMS Affects User Profile Management