Description
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
Remediation
References
Related Vulnerabilities
axios Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-28168)
WordPress Plugin Facebook Like Box Multiple Vulnerabilities (2.9.1)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-1103)
WordPress Plugin Htaccess by BestWebSoft Cross-Site Scripting (1.7.5)
WordPress Plugin Qwizcards-online quizzes and flashcards Cross-Site Scripting (3.61)