Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2021-40662
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
0
Attacker Value
Unknown
CVE-2021-38745
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
0
Attacker Value
Unknown
CVE-2021-43687
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
0
Attacker Value
Unknown
CVE-2021-37389
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
0
Attacker Value
Unknown
CVE-2021-26746
Disclosure Date: February 19, 2021 (last updated February 22, 2025)
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
0