CVE-2021-37391: XSS
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-37391?
CVE-2021-37391 is a vulnerability in Chamilo LMS 1.11.14 that allows users without privileges to send invitation messages and exploit a stored XSS vulnerability.
What is the severity of CVE-2021-37391?
The severity of CVE-2021-37391 is medium, with a CVSS score of 5.4.
How does CVE-2021-37391 affect Chamilo LMS?
CVE-2021-37391 affects Chamilo LMS versions between 1.11.0 and 1.11.14.
How can an attacker exploit CVE-2021-37391?
An attacker can exploit CVE-2021-37391 by sending an invitation message to another user, such as an administrator, and execute arbitrary code or steal cookies on the administration side through a stored XSS vulnerability in the social networking feature.
Are there any references for CVE-2021-37391?
Yes, you can find references for CVE-2021-37391 at the following links: [Link 1](https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chamilo-lms-1.11.14-xss-vulnerabilities) and [Link 2](https://github.com/chamilo/chamilo-lms/commit/de43a77049771cce08ea7234c5c1510b5af65bc8).