VYPR

Lms

by Chamilo

Source repositories

CVEs (151)

  • CVE-2023-37067MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.

  • CVE-2023-37066MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.

  • CVE-2023-37065MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.

  • CVE-2023-37064MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.

  • CVE-2023-37063MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.

  • CVE-2023-37062MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.

  • CVE-2023-37061MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.

  • CVE-2023-34962HigJun 8, 2023
    risk 0.00cvss 8.1epss 0.01

    Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.

  • CVE-2023-34961MedJun 8, 2023
    risk 0.00cvss 6.1epss 0.00

    Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.

  • CVE-2023-34959MedJun 8, 2023
    risk 0.00cvss 5.3epss 0.01

    An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.

  • CVE-2023-34958MedJun 8, 2023
    risk 0.00cvss 4.3epss 0.00

    Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.

Page 8 of 8