CVE-2023-37066: XSS
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Chamilo vulnerability?
The vulnerability ID for this Chamilo vulnerability is CVE-2023-37066.
What is the severity of CVE-2023-37066?
The severity of CVE-2023-37066 is medium (4.8).
How does CVE-2023-37066 affect Chamilo?
CVE-2023-37066 allows users with admin privilege accounts to insert XSS in the skills wheel in Chamilo 1.11.x up to 1.11.20.
What is the fix for CVE-2023-37066?
The fix for CVE-2023-37066 can be found in the following commit: [https://github.com/chamilo/chamilo-lms/commit/4f7b5ebf90c35999917c231276e47a4184275690](https://github.com/chamilo/chamilo-lms/commit/4f7b5ebf90c35999917c231276e47a4184275690)
Where can I find more information about CVE-2023-37066?
More information about CVE-2023-37066 can be found in the following link: [https://support.chamilo.org/projects/1/wiki/Security_issues#Issue-114-2023-06-06-Low-impact-Low-risk-XSS-through-admin-account-skills](https://support.chamilo.org/projects/1/wiki/Security_issues#Issue-114-2023-06-06-Low-impact-Low-risk-XSS-through-admin-account-skills)