CVE-2020-23127: CSRF
Published May 5, 2021
·Updated
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edituser function by targeting an admin user.
Affected Software
1 affected component
Chamilo Chamilo LMS=1.11.10
Remediation
Event History
May 5, 2021
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23127?
CVE-2020-23127 is a vulnerability in Chamilo LMS 1.11.10 that allows Cross Site Request Forgery (CSRF) attacks.
2
How does CVE-2020-23127 affect Chamilo LMS 1.11.10?
CVE-2020-23127 affects Chamilo LMS 1.11.10 by allowing unauthorized users to perform actions on the system through a CSRF attack.
3
What is the severity of CVE-2020-23127?
CVE-2020-23127 has a severity rating of 8.8 (high).
4
How can I fix CVE-2020-23127?
To fix CVE-2020-23127, it is recommended to upgrade to the latest version of Chamilo LMS and apply any security patches provided by the vendor.
5
Where can I find more information about CVE-2020-23127?
You can find more information about CVE-2020-23127 on the Chamilo LMS support website and a blog post detailing the vulnerability.