Lms
by Chamilo
Source repositories
CVEs (151)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37067 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section. | ||
| CVE-2023-37066 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel. | ||
| CVE-2023-37065 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section. | ||
| CVE-2023-37064 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section. | ||
| CVE-2023-37063 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section. | ||
| CVE-2023-37062 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition. | ||
| CVE-2023-37061 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section. | ||
| CVE-2023-34962 | Hig | 0.00 | 8.1 | 0.01 | Jun 8, 2023 | Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes. | ||
| CVE-2023-34961 | Med | 0.00 | 6.1 | 0.00 | Jun 8, 2023 | Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field. | ||
| CVE-2023-34959 | Med | 0.00 | 5.3 | 0.01 | Jun 8, 2023 | An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools. | ||
| CVE-2023-34958 | Med | 0.00 | 4.3 | 0.00 | Jun 8, 2023 | Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID. |
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.
- risk 0.00cvss 8.1epss 0.01
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
- risk 0.00cvss 6.1epss 0.00
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
- risk 0.00cvss 5.3epss 0.01
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
- risk 0.00cvss 4.3epss 0.00
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
Page 8 of 8