Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2022
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
CVSS Score
7.2
EPSS Score
0.006
Published
2022-04-15
A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.
CVSS Score
6.1
EPSS Score
0.005
Published
2022-04-15
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.
CVSS Score
9.8
EPSS Score
0.007
Published
2022-04-15
Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php.
CVSS Score
6.1
EPSS Score
0.005
Published
2022-04-15
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
CVSS Score
8.8
EPSS Score
0.004
Published
2022-04-15
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur
CVSS Score
7.8
EPSS Score
0.155
Published
2022-04-15
The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676)
CVSS Score
7.5
EPSS Score
0.005
Published
2022-04-15
CVE-2022-26904
Known exploited
Windows User Profile Service Elevation of Privilege Vulnerability
CVSS Score
7.0
EPSS Score
0.304
Published
2022-04-15
Azure SDK for .NET Information Disclosure Vulnerability
CVSS Score
5.3
EPSS Score
0.005
Published
2022-04-15
Skype for Business and Lync Spoofing Vulnerability
CVSS Score
5.3
EPSS Score
0.035
Published
2022-04-15


Contact Us

Shodan ® - All rights reserved