CVE-2018-20328 describes a low-risk Cross-Site Scripting (XSS) vulnerability in Chamilo LMS version 1.11.8, specifically within the main/social/group_view.php component of the social groups tool. This flaw allows authenticated users to inject malicious scripts that could affect other users, provided administrators have granted specific permissions. The vulnerability has a CVSS score of 5.4 (Medium), indicating a low-complexity attack requiring user interaction, with potential for limited impact on confidentiality and integrity. The attack vector is network-based, and successful exploitation requires prior authentication. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical low attention given to the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.11.8CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:1.11.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.