PT-2022-18415 · Unknown · Chamilo Lms

Published

2022-04-15

·

Updated

2023-08-08

·

CVE-2022-27421

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS version 1.11.13
Description The issue is related to a lack of validation on the user modification form, which allows attackers to escalate privileges to Platform Admin.
Recommendations For Chamilo LMS version 1.11.13, update to a version that includes the necessary validation on the user modification form to prevent privilege escalation. As a temporary workaround, consider restricting access to the user modification form to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-27421

Affected Products

Chamilo Lms