Description
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Change WordPress Login Logo Cross-Site Scripting (1.1.4)
Ruby on Rails Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-8162)
Elgg Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-3964)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.1)
WordPress Plugin Custom 404 Pro Cross-Site Scripting (3.2.7)