CVE-2023-37062

MEDIUM

Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Course Category Definition

Title source: llm
STIX 2.1

Description

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.

Scores

CVSS v3 4.8
EPSS 0.0033
EPSS Percentile 24.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
chamilo/chamilo 1.11.0 - 1.11.20
Published Jul 07, 2023
Tracked Since Feb 18, 2026