Cross Site Scripting Vulnerability in Chamilo Learning Management System
CVE-2023-31804

5.4MEDIUM

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
9 May 2023

What is CVE-2023-31804?

A cross site scripting vulnerability exists in Chamilo Learning Management System version 1.11.18, which allows local attackers to exploit course category parameters. By injecting malicious scripts, an attacker could potentially execute arbitrary code, compromising the integrity and security of the affected system. This vulnerability underscores the importance of robust input validation strategies to mitigate such risks and enhance overall security.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.