exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Chamilo LCMS Connect 4.1 Cross Site Scripting

Chamilo LCMS Connect 4.1 Cross Site Scripting
Posted Jan 1, 2016
Authored by Vadodil Joel Varghese

Chamilo LCMS Connect version 4.1 suffers from a persistent cross site scripting vulnerability. Originally added in March of 2015 but has since been updated with new information.

tags | exploit, xss
SHA-256 | b5e01df77db1dc82d6cd9768886ae5f007c2a46c66507269d6cdc9902e711752

Chamilo LCMS Connect 4.1 Cross Site Scripting

Change Mirror Download
#Affected Vendor: http://lcms.chamilo.org/
#Date: 27/03/2015
#Discovered by: Joel Vadodil Varghese
#Type of vulnerability: Stored XSS
#Tested on: Windows 7
#Product: LCMS Connect
#Version: 4.1
#Description: Chamilo is an open-source (under GNU/GPL licensing)
e-learning and content management system, aimed at improving access to
education and knowledge globally. Chamilo LCMS is a completely new software
platform for e-learning and collaboration. Chamilo LCMS connect is
vulnerable to stored xss vulnerability. The parameter "site_name" is the
vulnerable parameter which will lead to its compromise.

#Proof of Concept (PoC): site_name=<img src="" onerror="alert('XSS')"/>

*Reported to Vendor:* 28 Mar 2015
*Patch Confirmation:* 01 Apr 2015

*References:*
*Mail sent to Vendor: *
http://lists.chamilo.org/pipermail/dev-lcms/2015-April/015386.html
*Patch Confirmation:*
https://bitbucket.org/chamilo/core/commits/96bc613dccebb91c80d53457432b0fd2fbe3dece
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close