CVE-2021-37390: XSS
Published Aug 10, 2021
·Updated
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
Affected Software
1 affected component
Chamilo Chamilo LMS<1.11.14
Remediation
Event History
Aug 10, 2021
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37390?
CVE-2021-37390 is a reflected XSS vulnerability in Chamilo LMS version 1.11.14.
2
What is the severity of CVE-2021-37390?
CVE-2021-37390 has a severity level of medium.
3
How does CVE-2021-37390 affect Chamilo LMS?
CVE-2021-37390 affects Chamilo LMS versions up to and including 1.11.14.
4
What is the Common Weakness Enumeration (CWE) of CVE-2021-37390?
The CWE for CVE-2021-37390 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2021-37390?
To fix CVE-2021-37390, it is recommended to update Chamilo LMS to a version higher than 1.11.14.