Chamilo
cpe:2.3:a:chamilo:chamilo:*:*:*:*:*:*:*, +1 more
- <= 1.11.28
A vulnerability allowing HTML injection has been identified in Chamilo Learning Management System versions prior to 1.11.30. The issue arises in the help.php file, where the open parameter is not properly sanitized, enabling attackers to inject arbitrary HTML, such as underlined text, through a crafted URL. This vulnerability has been addressed in version 1.11.30.
Exploitation of this vulnerability allows for HTML injection, which could be leveraged for cross-site scripting (XSS) attacks, as confirmed by the vulnerability reporter.
To reproduce this vulnerability, send a request to the help.php file with a crafted URL that includes an unescaped HTML tag, such as an underline tag. The injected HTML will be rendered, demonstrating the successful exploitation of the vulnerability.
Users can upgrade to Chamilo version 1.11.30 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.