Show filters
74 Total Results
Displaying 61-70 of 74
Sort by:
Attacker Value
Unknown

CVE-2013-0739

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.
Attacker Value
Unknown

CVE-2012-4030

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
Attacker Value
Unknown

CVE-2015-9540

Disclosure Date: January 04, 2020 (last updated February 21, 2025)
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
Attacker Value
Unknown

CVE-2019-13082

Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder in a ZIP archive, the server will accept this file without any checks. Because one can access this file from the website, it is remote code execution. This is related to a scorm imsmanifest.xml file, the import_package function, and extraction in $courseSysDir.$newDir.
0
Attacker Value
Unknown

CVE-2019-7383

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file network/isp/isp_update_edit.php does not properly validate user input, which leads to shell command injection via the des parameter.
Attacker Value
Unknown

CVE-2018-19525

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of csrf token validation.
0
Attacker Value
Unknown

CVE-2019-1000015

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.
0
Attacker Value
Unknown

CVE-2019-1000017

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable via ticket_id=[ticket number]. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.
0
Attacker Value
Unknown

CVE-2018-20328

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
0
Attacker Value
Unknown

CVE-2018-20327

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
0