Medium severity6.1NVD Advisory· Published Feb 8, 2020· Updated Jun 16, 2026
CVE-2012-4029
CVE-2012-4029
Description
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Chamilo/LMSdescription
Patches
Vulnerability mechanics
References
3- support.chamilo.org/attachments/download/2863/chamilo-1.8.8.4-to-1.8.8.6.patchnvdPatchVendor Advisory
- packetstormsecurity.com/files/115927/Chamilo-1.8.8.4-XSS-File-Deletion.htmlnvdExploitThird Party AdvisoryVDB Entry
- support.chamilo.org/projects/chamilo-18/wiki/Security_issuesnvdVendor Advisory
News mentions
0No linked articles in our index yet.