Description
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-3167 Vulnerability (CVE-2012-3167)
Apache HTTP Server CVE-2014-0098 Vulnerability (CVE-2014-0098)
Oracle Application Server Other Vulnerability (CVE-2006-5362)
WordPress Plugin Merge+Minify+Refresh Cross-Site Request Forgery (1.10.6)
WordPress Plugin Archivist-Custom Archive Templates Multiple Vulnerabilities (1.7.4)