Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2022-40407
Disclosure Date: September 29, 2022 (last updated October 08, 2023)
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
0
Attacker Value
Unknown
CVE-2021-40662
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
0
Attacker Value
Unknown
CVE-2021-38745
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
0
Attacker Value
Unknown
CVE-2021-43687
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
0
Attacker Value
Unknown
CVE-2020-23126
Disclosure Date: November 03, 2021 (last updated February 23, 2025)
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
0
Attacker Value
Unknown
CVE-2021-37389
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
0
Attacker Value
Unknown
CVE-2020-23128
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
0
Attacker Value
Unknown
CVE-2020-23127
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
0
Attacker Value
Unknown
CVE-2021-26746
Disclosure Date: February 19, 2021 (last updated February 22, 2025)
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
0
Attacker Value
Unknown
CVE-2019-13082
Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder in a ZIP archive, the server will accept this file without any checks. Because one can access this file from the website, it is remote code execution. This is related to a scorm imsmanifest.xml file, the import_package function, and extraction in $courseSysDir.$newDir.
0