Vulnerabilities
Vulnerable Software
Chamilo:  >> Chamilo Lms  >> 1.8.8  Security Vulnerabilities
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS Score
8.8
EPSS Score
0.197
Published
2023-11-28
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS Score
8.8
EPSS Score
0.026
Published
2023-11-28
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS Score
8.8
EPSS Score
0.026
Published
2023-11-28
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
CVSS Score
7.2
EPSS Score
0.015
Published
2023-11-28
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS Score
8.8
EPSS Score
0.026
Published
2023-11-28
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVSS Score
8.1
EPSS Score
0.93
Published
2023-11-28
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
CVSS Score
7.2
EPSS Score
0.015
Published
2023-11-28
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
CVSS Score
7.2
EPSS Score
0.006
Published
2022-04-15
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
CVSS Score
6.1
EPSS Score
0.003
Published
2021-08-10
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
CVSS Score
7.5
EPSS Score
0.005
Published
2020-01-10


Contact Us

Shodan ® - All rights reserved