Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2023-31807

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
Attacker Value
Unknown

CVE-2023-31806

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.
Attacker Value
Unknown

CVE-2023-31805

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function.
Attacker Value
Unknown

CVE-2023-31804

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters.
Attacker Value
Unknown

CVE-2023-31803

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters.
Attacker Value
Unknown

CVE-2023-31802

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters.
Attacker Value
Unknown

CVE-2023-31801

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.
Attacker Value
Unknown

CVE-2023-31800

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.
Attacker Value
Unknown

CVE-2023-31799

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the system annnouncements parameter.
Attacker Value
Unknown

CVE-2022-42029

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.