ZeroHour

CVE-2024-51142

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p28
Published
()
Modified
Description

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

Vendors
chamilo
Products
chamilo lms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.