CVE-2018-20328 Information
Feb 14, 2021
cve
Description
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool allowing authenticated users to affect other users under specific conditions of permissions granted by administrators. This is considered \low risk\ due to the nature of the feature it exploits.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/chamilo/chamilo-lms/commit/5e61c2b0fcc938ca687b8d4e593b1500aa52a034 https://support.chamilo.org/projects/1/wiki/Security_issuesIssue-32-2018-11-28-Low-risk-More-XSS-and-path-disclosure-issues
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: