mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
18 lines
711 B
Markdown
18 lines
711 B
Markdown
### [CVE-2024-51142](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-51142)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://infosecwriteups.com/chamilo-lms-authentication-bypass-and-cross-site-scripting-stored-3fcb874ac7c1
|
|
|
|
#### Github
|
|
- https://github.com/fkie-cad/nvd-json-data-feeds
|
|
|