Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course learning path Settings field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.
An attacker injects malicious JavaScript code into the learning path settings field in a course. The injected code is permanently stored in the system and is automatically executed in the browser of every user who views the course information page. The malicious script can steal the victim's session cookies or authentication tokens, which can then be used by the attacker to impersonate a user with higher privileges (account takeover — ATO).
An attacker can take over accounts of users with higher privileges, including administrators, by stealing their session tokens or cookies. As a result, the attacker gains full control over the compromised accounts and potentially over the entire LMS platform.
Update Chamilo LMS to version 1.11.34 or later, in which the vulnerability has been fixed. The patch is available in the official Chamilo GitHub repository.
Chamilo LMS in all versions before 1.11.34
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HChamilo Lms
APPChamilo< 1.11.34
Related vulnerabilities
Chamilo LMS: ominięcie uwierzytelnienia i modyfikacja plików przez katalog install
OS Command Injection w Chamilo LMS — funkcja przenoszenia plików
Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)
Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora
Stored XSS w Chamilo LMS umożliwiający przejęcie kont administratorów