PT-2024-21931 · Unknown · Chamilo Lms

Angelfqc

·

Published

2024-11-01

·

Updated

2024-11-04

·

CVE-2024-27524

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS version 1.11.26
Description A Cross Site Scripting issue allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the "new ticket.php" component. This could potentially lead to data theft or malware spread.
Recommendations For Chamilo LMS version 1.11.26, patch immediately to prevent potential data theft or malware spread. As a temporary workaround, consider restricting access to the "new ticket.php" component or avoiding the use of the filename parameter until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-27524

Affected Products

Chamilo Lms