CVE-2018-20328
Summary
| CVE | CVE-2018-20328 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-21 06:29:00 UTC |
| Updated | 2019-01-07 13:37:00 UTC |
| Description | Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Chamilo | Chamilo Lms | 1.11.8 | All | All | All |
| Application | Chamilo | Chamilo Lms | 1.11.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Remove XSS from social groups page - refs #2746 · chamilo/chamilo-lms@5e61c2b · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Security issues - Chamilo LMS - Chamilo Tracking System | MISC | support.chamilo.org | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.