Overview
- Description
- Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online."
- Source
- cve@mitre.org
- NVD status
- Awaiting Analysis
Risk scores
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
Social media
- Hype score
- Not currently trending
CVE-2024-30619 Chamilo LMS 1.11.26 Incorrect Access Control Vulnerability Exposed Chamilo LMS Version 1.11.26 has an Incorrect Access Control issue. An attacker without authentication can access the message count... https://t.co/7MQHBFhc7t
@VulmonFeeds
4 Nov 2024
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-30619 Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users … https://t.co/CP6DogFOzx
@CVEnew
4 Nov 2024
442 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes