Campus Virtual · Campus Virtual-Lms · CVE-2009-2149
**Name of the Vulnerable Software and Affected Versions**
Campus Virtual-LMS (affected versions not specified)
**Description**
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerabilities can be exploited through the `courseid` parameter to `/enrolments/step1.php`, or the `search` or `siteid` parameters to `/files/shared list.php`.
**Recommendations**
For the affected versions, consider restricting access to the `/enrolments/step1.php` and `/files/shared list.php` API endpoints until a patch is available.
As a temporary workaround, avoid using the `courseid`, `search`, and `siteid` parameters in the affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.