VYPR
Medium severity5.4NVD Advisory· Published Aug 10, 2021· Updated Jun 17, 2026

CVE-2021-37391

CVE-2021-37391

Description

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Chamilo/Lms2 versions
    cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*range: >=1.11.0,<1.11.14
    • (no CPE)range: 1.11.14
  • Chamilo/Chamilo LMSdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.