CVE-2022-27422: XSS
Published Apr 15, 2022
·Updated
A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.
Affected Software
1 affected component
Chamilo Chamilo LMS>=1.11.0<=1.11.16
Remediation
Patch Available
Event History
Apr 15, 2022
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27422?
CVE-2022-27422 is a reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13.
2
How does CVE-2022-27422 affect Chamilo LMS?
The vulnerability allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.
3
How severe is CVE-2022-27422?
CVE-2022-27422 has a severity rating of 6.1 (medium).
4
Which versions of Chamilo LMS are affected by CVE-2022-27422?
Chamilo LMS versions 1.11.0 to 1.11.16 are affected by CVE-2022-27422.
5
How can I fix CVE-2022-27422?
To fix CVE-2022-27422, update Chamilo LMS to a version beyond 1.11.16.