CVE-2019-1000017: Medium severity chamilo lms vulnerability
Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable via ticketid=[ticket number]. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-1000017?
CVE-2019-1000017 is an Incorrect Access Control vulnerability in Chamilo-lms version 1.11.8 and earlier.
What is the severity of CVE-2019-1000017?
CVE-2019-1000017 has a severity rating of medium (6.5).
How can an attacker exploit CVE-2019-1000017?
An attacker can exploit CVE-2019-1000017 by using an authenticated user account to read all tickets available on the platform.
Is there a fix available for CVE-2019-1000017?
Yes, a fix is available for CVE-2019-1000017. Users should update to a version later than 1.11.8.
Where can I find more information about CVE-2019-1000017?
You can find more information about CVE-2019-1000017 in the references section of the vulnerability description.