CVE-2021-37391

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
Configurations

Configuration 1

cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*

Information

Published : 2021-08-10 08:15

Updated : 2021-08-19 05:05


NVD link : CVE-2021-37391

Mitre link : CVE-2021-37391

Products Affected
No products.
CWE