Chamilo LMS
cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*
- >= 1.11.0, <= 2.0-beta.1
A vulnerability in Chamilo LMS versions 1.11.0 prior to 2.0-beta.1 allows for malicious redirects through the 'redirect' parameter on the login page. This issue has been addressed in version 2.0-beta.2.
Exploitation of this vulnerability allows for open redirect attacks, where users can be sent to unintended destinations, potentially leading to phishing or other malicious activities.
Users can update to Chamilo LMS version 2.0-beta.2 to address this vulnerability. Additionally, the commit '73ae629' can be applied as a patch.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.