CVE-2009-2149

Campus Virtual-LMS - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) courseid parameter to enrolments/step1.php, or the (2) search or (3) siteid parameter to files/shared_list.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Yasión · textwebappsphp
https://www.exploit-db.com/exploits/8937

Scores

EPSS 0.0051
EPSS Percentile 66.2%

Classification

CWE
CWE-79
Status published

Affected Products (2)

campusvirtualcomputrade/campus_virtual-lms
n/a/n/a

Timeline

Published Jun 22, 2009
Tracked Since Feb 18, 2026