Chamilo LMS 是一个开源学习管理系统。从 2.0.0 到至少 2.1.0 版本,Chamilo LMS 在存储私密消息的 字段时未进行服务器端净化(sanitization),并在 和 中将其作为 HTML 内容直接渲染。 经过身份验证的低权限用户(包括普通学生)可以利用该漏洞,向管理员发送精心构造的消息内容,因为消息创建流程允许发送者选择其他用户(如管理员)作为接收者。当管理员打开常规收件箱或查看具体消息时,该内容会在其浏览器中执行,无需点击任何链接。这可能导致会话凭据泄露,或允许攻击者以管理员身份执行
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chamilo | chamilo-lms | >= 2.0.0, < 2.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet