CVE-2021-37391
Chamilo LMS 1.11.14 - Account Takeover
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
Un usuario sin privilegios en Chamilo LMS versión 1.11.14, puede enviar un mensaje de invitación a otro usuario, por ejemplo, el administrador, mediante los archivos main/social/search.php, main/inc/lib/social.lib.php y robar cookies o ejecutar código arbitrario en el lado de la administración por medio de una vulnerabilidad de tipo XSS almacenado por medio de la red social la funcionalidad send invitation de la red social
Chamilo LMS version 1.11.14 suffers from a persistent cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-21 CVE Reserved
- 2021-08-10 CVE Published
- 2022-02-02 First Exploit
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50694 | 2022-02-02 | |
https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chamilo-lms-1.11.14-xss-vulnerabilities | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://github.com/chamilo/chamilo-lms/commit/de43a77049771cce08ea7234c5c1510b5af65bc8 | 2021-08-19 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Chamilo Search vendor "Chamilo" | Chamilo Lms Search vendor "Chamilo" for product "Chamilo Lms" | >= 1.11.0 < 1.11.14 Search vendor "Chamilo" for product "Chamilo Lms" and version " >= 1.11.0 < 1.11.14" | - |
Affected
|