CVE-2021-40662: CSRF
Published Mar 21, 2022
·Updated
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
Affected Software
1 affected component
Chamilo Chamilo=1.11.14
Remediation
Event History
Mar 21, 2022
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
Description
Frequently Asked Questions
1
What is CVE-2021-40662?
CVE-2021-40662 is a Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.14 that allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
2
What is the severity of CVE-2021-40662?
The severity of CVE-2021-40662 is high with a CVSS score of 8.8.
3
What software versions are affected by CVE-2021-40662?
Chamilo LMS 1.11.14 is affected by CVE-2021-40662.
4
How can an attacker exploit CVE-2021-40662?
An attacker can exploit CVE-2021-40662 by tricking a user into clicking on a specially crafted URL that performs unauthorized actions on behalf of the user.
5
Is there a fix for CVE-2021-40662?
Yes, updating Chamilo LMS to a version that includes the patch for CVE-2021-40662 will fix the vulnerability.