PT-2020-7336 · Chamilo · Chamilo

Published

2020-01-30

·

Updated

2020-01-31

·

CVE-2013-0739

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Chamilo version 1.9.4
Description: The issue arises from improper validation of user-supplied input by the chat.php script, leading to a cross-site scripting (XSS) problem. XSS is a security vulnerability that occurs when an application includes user-supplied data in its output without properly validating or encoding it, allowing an attacker to inject malicious scripts into the application.
Recommendations: For Chamilo version 1.9.4, consider disabling the chat.php script until a patch is available to prevent exploitation of the XSS issue. Restrict access to the chat functionality to minimize the risk of malicious script injection. Avoid using the chat feature with untrusted input until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0739

Affected Products

Chamilo