Cross Site Scripting Vulnerability in Chamilo LMS by Chamilo
CVE-2024-27524

Currently unrated

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
1 November 2024

What is CVE-2024-27524?

A Cross Site Scripting vulnerability exists in Chamilo LMS version 1.11.26, allowing attackers to execute malicious scripts via the crafted filename parameter in the new_ticket.php component. This flaw could potentially enable remote attackers to escalate privileges and execute arbitrary code in the context of the affected application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-27524 : Cross Site Scripting Vulnerability in Chamilo LMS by Chamilo