LiveActive security incident?Get immediate response
CVE Record

CVE-2021-37391: A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the...

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Chamilo LMS 1.11.14 has a stored cross-site scripting issue in its social invitation feature. A low-privilege user can send a crafted invitation to another user, including an administrator, causing script execution when viewed. Business risk is highest where Chamilo admins use the affected social features.

Executive priority

Prioritize remediation for internet-facing or administrator-heavy Chamilo deployments. The issue can turn a normal user account into a path for administrator browser compromise, but available evidence does not show known active exploitation.

Technical view

The CVE describes stored XSS through Chamilo LMS 1.11.14 social invitation handling involving main/social/search.php and main/inc/lib/social.lib.php. The reported impact includes cookie theft or arbitrary client-side code execution in an administrator’s browser context. The source bundle does not provide CVSS, CWE, or a named fixed release.

Likely exposure

Exposure is limited to organizations running Chamilo LMS 1.11.14 with the social network invitation feature reachable by unprivileged users. Public internet exposure increases risk, but the provided sources do not identify other affected versions.

Exploitation context

The record describes a low-privilege user targeting another user via stored invitation content. There is no KEV listing and no provided evidence of active exploitation in the source bundle.

Researcher notes

Evidence is sparse: the CVE record names Chamilo LMS 1.11.14, specific files, and the social invitation feature, but omits CVSS and detailed affected-version range. Treat other versions as unconfirmed unless vendor materials verify them.

Mitigation direction

  • Check Chamilo vendor guidance and upgrade to a fixed version if available.
  • Review the referenced upstream commit before treating the issue as remediated.
  • Restrict or disable social invitation functionality until remediation is verified.
  • Limit administrative use of affected social features on untrusted content.
  • Apply session-cookie hardening and administrative browser protections where supported.

Validation and detection

  • Inventory Chamilo LMS instances and confirm whether version 1.11.14 is present.
  • Verify whether the social invitation feature is enabled and reachable by low-privilege users.
  • Confirm deployed code includes the referenced upstream fix or later vendor release.
  • Review logs for unusual social invitations sent to administrators.
  • Regression-test invitation rendering for safe output encoding after remediation.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-37391 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.