XSS Vulnerability in Chamilo LMS Affects User Profile Management
CVE-2020-23126
6.1MEDIUM
What is CVE-2020-23126?
Chamilo LMS version 1.11.10 is susceptible to a cross-site scripting (XSS) vulnerability in the personal profile edition form. This flaw allows an attacker to execute arbitrary scripts in the context of the user's session, affecting both the user and their social network friends. Users are encouraged to update to the latest version and apply necessary security measures to protect their information.