Cross Site Request Forgery Vulnerability in Chamilo LMS by Chamilo
CVE-2020-23127

8.8HIGH

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
6 May 2021

What is CVE-2020-23127?

The vulnerability in Chamilo LMS version 1.11.10 allows attackers to exploit the edit_user function through Cross Site Request Forgery (CSRF). This could target admin users, enabling unauthorized actions on behalf of legitimate users and potentially compromising the integrity of the system. Proper safeguards are essential to prevent this type of attack and protect sensitive administrative functions.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.