Description
|
|
Multiple vulnerabilities have been identified in Campus Virtual-LMS, which could be exploited by attackers to manipulate or disclose certain data.
The first issues are caused by input validation errors in the "enrolments/step1.php", "files/shared_list.php" and "files/shared_list.php" scripts when processing the "courseid", "search" and "siteid" parameters, which could allow cross site scripting attacks.
The second vulnerability is caused by an input validation error in the "news/index.php" script when processing the "id" parameter, which could be exploited by malicious people to conduct SQL injection attacks.
|