CVE-2023-37064: XSS
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-37064?
CVE-2023-37064 is a vulnerability in Chamilo 1.11.x up to 1.11.20 that allows users with admin privilege accounts to insert XSS in the extra fields management section.
What is the severity of CVE-2023-37064?
The severity of CVE-2023-37064 is medium with a CVSS score of 4.8.
How can users exploit CVE-2023-37064?
Users with admin privilege accounts can exploit CVE-2023-37064 by inserting XSS in the extra fields management section.
How can I fix CVE-2023-37064?
To fix CVE-2023-37064, you should update Chamilo to version 1.11.21 or later, as the vulnerability has been patched in the latest versions.
Where can I find more information about CVE-2023-37064?
You can find more information about CVE-2023-37064 at the following references: [GitHub](https://github.com/chamilo/chamilo-lms/commit/91ecc6141de6de9483c5a31fbb9fa91450f24940) and [Chamilo Support](https://support.chamilo.org/projects/1/wiki/Security_issues#Issue-119-2023-06-06-Low-impact-Low-risk-XSS-through-admin-account-extra-fields-management).