Cross-Site Scripting Vulnerability in Chamilo LMS by Chamilo Foundation
CVE-2023-37067
4.8MEDIUM
What is CVE-2023-37067?
Chamilo LMS versions 1.11.x up to 1.11.20 are susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw allows users with administrative privileges to inject malicious scripts into the management section for user groups. If exploited, this vulnerability could lead to unauthorized actions and impact user data integrity and confidentiality. Users and administrators should apply recommended patches and updates to safeguard their systems against this and similar vulnerabilities.