Security readout for executives and security teams
Plain-English summary
Chamilo LMS 1.11.14 has a stored cross-site scripting issue in its social invitation feature. A low-privilege user can send a crafted invitation to another user, including an administrator, causing script execution when viewed. Business risk is highest where Chamilo admins use the affected social features.
Executive priority
Prioritize remediation for internet-facing or administrator-heavy Chamilo deployments. The issue can turn a normal user account into a path for administrator browser compromise, but available evidence does not show known active exploitation.
Technical view
The CVE describes stored XSS through Chamilo LMS 1.11.14 social invitation handling involving main/social/search.php and main/inc/lib/social.lib.php. The reported impact includes cookie theft or arbitrary client-side code execution in an administrator’s browser context. The source bundle does not provide CVSS, CWE, or a named fixed release.
Likely exposure
Exposure is limited to organizations running Chamilo LMS 1.11.14 with the social network invitation feature reachable by unprivileged users. Public internet exposure increases risk, but the provided sources do not identify other affected versions.
Exploitation context
The record describes a low-privilege user targeting another user via stored invitation content. There is no KEV listing and no provided evidence of active exploitation in the source bundle.
Researcher notes
Evidence is sparse: the CVE record names Chamilo LMS 1.11.14, specific files, and the social invitation feature, but omits CVSS and detailed affected-version range. Treat other versions as unconfirmed unless vendor materials verify them.
Mitigation direction
- Check Chamilo vendor guidance and upgrade to a fixed version if available.
- Review the referenced upstream commit before treating the issue as remediated.
- Restrict or disable social invitation functionality until remediation is verified.
- Limit administrative use of affected social features on untrusted content.
- Apply session-cookie hardening and administrative browser protections where supported.
Validation and detection
- Inventory Chamilo LMS instances and confirm whether version 1.11.14 is present.
- Verify whether the social invitation feature is enabled and reachable by low-privilege users.
- Confirm deployed code includes the referenced upstream fix or later vendor release.
- Review logs for unusual social invitations sent to administrators.
- Regression-test invitation rendering for safe output encoding after remediation.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-37391 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/chamilo/chamilo-lms/commit/de43a77049771cce08ea7234c5c1510b5af65bc8CVE reference · x_refsource_MISC
- https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chamilo-lms-1.11.14-xss-vulnerabilitiesCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
