First published: Fri Nov 01 2024(Updated: )
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo LMS | ||
Chamilo LMS | =1.11.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27524 is considered a high severity Cross Site Scripting vulnerability.
To fix CVE-2024-27524, you should update Chamilo LMS to version 1.11.27 or later.
The CVE-2024-27524 vulnerability affects the new_ticket.php component of Chamilo LMS.
Yes, CVE-2024-27524 can be exploited remotely by an attacker to escalate privileges.
CVE-2024-27524 specifically affects Chamilo LMS version 1.11.26.