Jump to content
Aerosol

Chamilo LCMS Connect 4.1 Cross Site Scripting

Recommended Posts

Posted

Hi Team,

#Affected Vendor: http://lcms.chamilo.org/
#Date: 27/03/2015
#Discovered by: Joel Vadodil Varghese
#Type of vulnerability: Persistent XSS
#Tested on: Windows 7
#Product: LCMS Connect
#Version: 4.1
#Description: Chamilo is an open-source (under GNU/GPL licensing)
e-learning and content management system, aimed at improving access to
education and knowledge globally.
Chamilo LCMS is a completely new software platform for e-learning and
collaboration. Chamilo LCMS connect is vulnerable to stored xss
vulnerability. The parameter "site_name" is the vulnerable parameter which
will lead to its compromise.
#Proof of Concept (PoC):
------------------------
site_name=<img src="" onerror="alert('XSS')"/>

--
Regards,

*Joel V*

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...