CVE-2023-34961
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-34961 refers to a cross-site scripting (XSS) vulnerability discovered in the Chamilo learning management system, affecting versions 1.11.x up to 1.11.18. The issue was identified in the /feedback/comment field, which could be exploited by attackers to inject malicious scripts into web pages viewed by other users. Successful exploitation could result in unauthorized access to sensitive information or the execution of malicious code, posing a significant risk to users of the affected Chamilo installations. It is crucial for administrators to apply the available patch or upgrade to a non-vulnerable version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Chamilo Lms
Affected Vendors
- Chamilo