Description
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
Remediation
References
Related Vulnerabilities
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.15)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.33)
IBM WebSEAL Missing Authorization Vulnerability (CVE-2019-4158)
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler Cross-Site Scripting (5.0.2)
WordPress Plugin Work The Flow File Upload Arbitrary File Upload (2.3.1)