CVE-2018-20328 Information

Description

Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool allowing authenticated users to affect other users under specific conditions of permissions granted by administrators. This is considered \low risk\ due to the nature of the feature it exploits.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/chamilo/chamilo-lms/commit/5e61c2b0fcc938ca687b8d4e593b1500aa52a034 https://support.chamilo.org/projects/1/wiki/Security_issuesIssue-32-2018-11-28-Low-risk-More-XSS-and-path-disclosure-issues

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: