VYPR
Medium severity6.8NVD Advisory· Published Mar 21, 2022· Updated Jun 17, 2026

CVE-2021-38745

CVE-2021-38745

Description

Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.

Affected products

3
  • cpe:2.3:a:chamilo:chamilo:1.11.14:-:*:*:*:*:*:*
  • Chamilo LMS/Chamilo LMSdescription
  • Chamilo/Lmsllm-fuzzy
    Range: <1.11.14

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.