Cross Site Scripting Vulnerability in Chamilo LMS by Chamilo
CVE-2023-31801
6.1MEDIUM
What is CVE-2023-31801?
A Cross Site Scripting vulnerability has been identified in Chamilo LMS version 1.11.18. This security flaw enables local attackers to exploit the 'skills wheel' parameter, resulting in the potential execution of arbitrary code. Users are advised to assess their systems for this vulnerability and apply the latest security patches to mitigate risks associated with this security issue.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
