Cross Site Scripting Vulnerability in Chamilo LMS by Chamilo
CVE-2024-27524
Currently unrated
What is CVE-2024-27524?
A Cross Site Scripting vulnerability exists in Chamilo LMS version 1.11.26, allowing attackers to execute malicious scripts via the crafted filename parameter in the new_ticket.php component. This flaw could potentially enable remote attackers to escalate privileges and execute arbitrary code in the context of the affected application.