CVE-2023-31802: XSS
Published May 9, 2023
·Updated
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedinurl parameters.
Affected Software
1 affected component
Chamilo Chamilo LMS=1.11.18
Event History
May 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-31802?
The severity of CVE-2023-31802 is medium with a score of 5.4.
2
What is the affected software of CVE-2023-31802?
The affected software of CVE-2023-31802 is Chamilo Lms version 1.11.18.
3
How can a local attacker exploit CVE-2023-31802?
A local attacker can exploit CVE-2023-31802 by executing arbitrary code through the skype and linedin_url parameters.
4
Is there a fix available for CVE-2023-31802?
Yes, please refer to the security advisory for instructions on how to fix CVE-2023-31802.
5
What is the Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability is CVE-2023-31802.