VYPR

Chamilo

by Chamilo

Source repositories

CVEs (105)

  • CVE-2023-37061MedJul 7, 2023
    risk 0.00cvss 4.8epss 0.00

    Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.

  • CVE-2021-37390MedAug 10, 2021
    risk 0.00cvss 6.1epss 0.01

    A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

  • CVE-2021-37389MedAug 10, 2021
    risk 0.00cvss 6.1epss 0.01

    Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

  • CVE-2021-32925MedMay 13, 2021
    risk 0.00cvss 6.5epss 0.02

    admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.

  • CVE-2021-26746MedFeb 19, 2021
    risk 0.00cvss 6.1epss 0.01

    Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.

Page 6 of 6