PT-2021-3968 · Unknown · Chamilo Lms
Published
2021-08-10
·
Updated
2022-02-03
·
CVE-2021-37391
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Chamilo LMS version 1.11.14
Description
The issue allows a user without privileges to send an invitation message to another user, such as the administrator, through
main/social/search.php and main/inc/lib/social.lib.php, potentially stealing cookies or executing arbitrary code on the administration side via a stored XSS vulnerability in the social network's send invitation feature. This can be exploited by a remote attacker to execute arbitrary code.Recommendations
For Chamilo LMS version 1.11.14, as a temporary workaround, consider disabling the
main/social/search.php and main/inc/lib/social.lib.php functions until a patch is available. Restrict access to the social network's send invitation feature to minimize the risk of exploitation. Avoid using the send invitation feature in the social network until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chamilo Lms