CVE-2018-20327 Information
Feb 14, 2021
cve
Description
Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool allowing authenticated users to affect other users under specific conditions of permissions granted by administrators. This is considered \low risk\ due to the nature of the feature it exploits.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/chamilo/chamilo-lms/commit/814049e5bd5317d761dda0ebbbc519cb2a64ab6c https://support.chamilo.org/projects/1/wiki/Security_issuesIssue-32-2018-11-28-Low-risk-More-XSS-and-path-disclosure-issues
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: