Chamilo
cpe:2.3:a:chamilo:chamilo:*:*:*:*:*:*:*, +1 more
- <= 1.11.28
A stored cross-site scripting vulnerability has been identified in Chamilo Learning Management System, specifically in the glossary feature. This issue affects versions prior to 1.11.30. The vulnerability allows users with the Teacher role to inject malicious JavaScript into glossary terms, which is then executed when an administrator views the course log resources.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the glossary.
To reproduce this vulnerability, log in as a Teacher and create a course. Add a glossary term, injecting JavaScript into the 'term' parameter. After saving, log in as an administrator and access the course's tracking section, where the injected script will execute.
Users can update to Chamilo version 1.11.30 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.