Cross Site Scripting Vulnerability in Chamilo LMS by Chamilo
CVE-2023-31801

6.1MEDIUM

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
9 May 2023

What is CVE-2023-31801?

A Cross Site Scripting vulnerability has been identified in Chamilo LMS version 1.11.18. This security flaw enables local attackers to exploit the 'skills wheel' parameter, resulting in the potential execution of arbitrary code. Users are advised to assess their systems for this vulnerability and apply the latest security patches to mitigate risks associated with this security issue.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.