PT-2019-11267 · Chamilo · Chamilo Lms
Published
2019-02-04
·
Updated
2019-02-20
·
CVE-2019-1000015
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Chamilo-lms versions 1.11.8 and earlier
Description:
The issue allows an attacker to send a message to the Administrator with a Cross Site Scripting (XSS) payload, potentially stealing cookies. This can be achieved by creating a ticket with a XSS payload in the subject field, for example using
<svg/onload=alert(1)> as the payload. This makes it possible to obtain the cookies of all users that have permission to view the tickets.Recommendations:
For versions 1.11.8 and earlier, update to a version after commit 33e2692a37b5b6340cf5bec1a84e541460983c03 to resolve the issue. As a temporary workaround, consider restricting access to the
main/messages/new message.php, main/social/personal data.php, main/inc/lib/TicketManager.php, and main/ticket/ticket details.php files to minimize the risk of exploitation. Avoid using the subject field in the ticket creation process until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chamilo Lms