PT-2024-34537 · Unknown · Chamilo Lms

CVE-2024-51142

·

Published

2024-11-15

·

Updated

2024-11-18

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Chamilo LMS version 1.11.26
Description: The issue is a Cross Site Scripting (XSS) vulnerability that allows an attacker to execute arbitrary code. This is achieved via the svkey parameter of the "storageapi.php" file.
Recommendations: For Chamilo LMS version 1.11.26, consider disabling access to the storageapi.php file or restricting the use of the svkey parameter until a patch is available. Avoid using the svkey parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-51142

Affected Products

Chamilo Lms