CVE-2024-51142

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
Configurations

No configuration.

History

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de cross site scripting en Chamilo LMS v.1.11.26 permite a un atacante ejecutar código arbitrario a través del parámetro svkey del archivo storageapi.php.

15 Nov 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79

15 Nov 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 19:15

Updated : 2024-11-18 17:11


NVD link : CVE-2024-51142

Mitre link : CVE-2024-51142

CVE.ORG link : CVE-2024-51142


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')