---
id: CVE-2021-43687
title: >-
  chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability
  in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the
  cookie.
summary: >-
  chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability
  in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the
  cookie.
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: chamilo
product: chamilo
affected:
  - chamilo = 1.11.14
published: '2021-12-01'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-43687'
references:
  - url: >-
      https://github.com/chamilo/chamilo-lms/blob/v1.11.14/plugin/jcapture/applet.php
    label: cve@mitre.org
  - url: 'https://github.com/chamilo/chamilo-lms/tree/v1.11.14'
    label: cve@mitre.org
  - url: >-
      https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-92-2021-11-12-Low-impact-Low-risk-XSS-Vulnerability-in-jCapture-plugin-CVE-2021-43687
    label: cve@mitre.org
  - url: 'http://chamilo-lms.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/chamilo/chamilo-lms/blob/v1.11.14/plugin/jcapture/applet.php
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/chamilo/chamilo-lms/tree/v1.11.14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-92-2021-11-12-Low-impact-Low-risk-XSS-Vulnerability-in-jCapture-plugin-CVE-2021-43687
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01199
epssPercentile: 0.66791
ingestedAt: '2026-07-06T01:08:17.065Z'
---

## Overview

chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.

## Affected

- `chamilo = 1.11.14`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
