Show filters
74 Total Results
Displaying 11-20 of 74
Sort by:
Attacker Value
Unknown

CVE-2023-3368

Disclosure Date: November 28, 2023 (last updated December 05, 2023)
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
Attacker Value
Unknown

CVE-2023-39582

Disclosure Date: September 01, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.
Attacker Value
Unknown

CVE-2023-39061

Disclosure Date: August 21, 2023 (last updated October 08, 2023)
Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-37067

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
Attacker Value
Unknown

CVE-2023-37066

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
Attacker Value
Unknown

CVE-2023-37065

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
Attacker Value
Unknown

CVE-2023-37064

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
Attacker Value
Unknown

CVE-2023-37063

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
Attacker Value
Unknown

CVE-2023-37062

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
Attacker Value
Unknown

CVE-2023-37061

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.