Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.
An attacker with a low-privilege account (e.g., instructor) can inject malicious JavaScript code into the course description field. This code is permanently stored in the system (stored XSS) and automatically executed in the browser of every user who views the page with course information. In this way, the attacker can intercept the victim's session cookies or authentication tokens and use them to take over their account.
An attacker can steal session cookies or authentication tokens of any user viewing the infected course, including administrators, leading to complete account takeover.
Chamilo LMS should be updated to version 1.11.34, in which the vulnerability has been patched. The patch is available in the official GitHub repository of the vendor.
Chamilo LMS in all versions before 1.11.34
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HChamilo Lms
APPChamilo< 1.11.34
Related vulnerabilities
Chamilo LMS: ominięcie uwierzytelnienia i modyfikacja plików przez katalog install
OS Command Injection w Chamilo LMS — funkcja przenoszenia plików
Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)
Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora
Stored XSS w Chamilo LMS — przejęcie kont wyżej uprzywilejowanych użytkowników