First published: Tue May 09 2023(Updated: )
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo Lms | =1.11.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31807 is a Cross Site Scripting (XSS) vulnerability found in Chamilo Lms v.1.11.18.
CVE-2023-31807 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function in Chamilo Lms v.1.11.18.
The severity of CVE-2023-31807 is medium (5.4).
To fix CVE-2023-31807, it is recommended to update Chamilo Lms to a version that includes a security patch or upgrade to a newer version.
You can find more information about CVE-2023-31807 on the Chamilo website and the Chamilo Lms support page for security issues.