CVE-2018-20327 Information

Description

Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool allowing authenticated users to affect other users under specific conditions of permissions granted by administrators. This is considered \low risk\ due to the nature of the feature it exploits.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/chamilo/chamilo-lms/commit/814049e5bd5317d761dda0ebbbc519cb2a64ab6c https://support.chamilo.org/projects/1/wiki/Security_issuesIssue-32-2018-11-28-Low-risk-More-XSS-and-path-disclosure-issues

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: