CVE-2012-4029: XSS
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the categoryname parameter in an addsentcategory action.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2012-4029?
CVE-2012-4029 is a cross-site scripting (XSS) vulnerability in Chamilo LMS before version 1.8.8.6.
How does CVE-2012-4029 affect Chamilo LMS?
CVE-2012-4029 allows remote attackers to inject arbitrary web scripts or HTML by exploiting the category_name parameter in an addsentcategory action in main/dropbox/index.php.
What is the severity level of CVE-2012-4029?
CVE-2012-4029 has a severity level of medium with a CVSS score of 6.1.
How can I fix CVE-2012-4029 in Chamilo LMS?
To fix CVE-2012-4029, update Chamilo LMS to version 1.8.8.6 or later.
Where can I find more information about CVE-2012-4029?
You can find more information about CVE-2012-4029 in the references provided: http://support.chamilo.org/attachments/download/2863/chamilo-1.8.8.4-to-1.8.8.6.patch, https://packetstormsecurity.com/files/115927/Chamilo-1.8.8.4-XSS-File-Deletion.html, and https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-7-2012-07-16-Moderate-risk-Several-moderate-security-flaws.