CVE-2018-20327
Summary
| CVE | CVE-2018-20327 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-21 06:29:00 UTC |
| Updated | 2019-01-07 13:43:00 UTC |
| Description | Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Chamilo | Chamilo Lms | 1.11.8 | All | All | All |
| Application | Chamilo | Chamilo Lms | 1.11.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Escape gradebook name in gradebook_list.php to avoid XSS - refs #2746 · chamilo/chamilo-lms@814049e · GitHub | MISC | github.com | Patch, Vendor Advisory |
| Security issues - Chamilo LMS - Chamilo Tracking System | MISC | support.chamilo.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.