Vendor CVEs
Chamilo
All CVEs
153 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-52470 | Med | 0.00 | 4.8 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by improper sanitization of the Category Name field, allowing privileged users to… | ||
| CVE-2025-52469 | Hig | 0.00 | 7.1 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can… | ||
| CVE-2025-52468 | Hig | 0.00 | 8.8 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username"… | ||
| CVE-2025-50198 | Med | 0.00 | 4.9 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version… | ||
| CVE-2025-50197 | Hig | 0.00 | 7.2 | 0.03 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50196 | Hig | 0.00 | 7.2 | 0.03 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50195 | Hig | 0.00 | 7.2 | 0.03 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50194 | Hig | 0.00 | 7.2 | 0.03 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50193 | Hig | 0.00 | 7.2 | 0.03 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30. | ||
| CVE-2025-52482 | Hig | 0.00 | 8.3 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50192 | Cri | 0.00 | 9.8 | 0.01 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50191 | Hig | 0.00 | 7.2 | 0.01 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50190 | Cri | 0.00 | 9.8 | 0.01 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30. | ||
| CVE-2025-50189 | Hig | 0.00 | 8.8 | 0.01 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] and POST login parameters found in /main/coursecopy/copy_course_session_selected.p… | ||
| CVE-2025-50188 | Hig | 0.00 | 7.2 | 0.01 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following scripts: /plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php,… | ||
| CVE-2025-50186 | Med | 0.00 | 4.8 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists due to insufficient sanitization of CSV filenames. An attacker can upload a maliciously named CSV file (e.g., .csv) that leads… | ||
| CVE-2024-50337 | Med | 0.00 | 5.3 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28. | ||
| CVE-2024-30619 | Hig | 0.00 | 7.5 | 0.00 | Nov 4, 2024 | Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online." | ||
| CVE-2024-30618 | Med | 0.00 | 6.1 | 0.00 | Nov 4, 2024 | A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'. | ||
| CVE-2024-30617 | Med | 0.00 | 5.4 | 0.00 | Nov 4, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge. | ||
| CVE-2024-27524 | Hig | 0.00 | 7.1 | 0.01 | Nov 1, 2024 | Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component. | ||
| CVE-2023-4226 | Hig | 0.00 | 8.8 | 0.02 | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | ||
| CVE-2023-4225 | Hig | 0.00 | 8.8 | 0.02 | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | ||
| CVE-2023-4224 | Hig | 0.00 | 8.8 | 0.02 | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | ||
| CVE-2023-4223 | Hig | 0.00 | 8.8 | 0.02 | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | ||
| CVE-2023-4222 | Hig | 0.00 | 7.2 | 0.04 | Nov 28, 2023 | Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | ||
| CVE-2023-4221 | Hig | 0.00 | 7.2 | 0.04 | Nov 28, 2023 | Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | ||
| CVE-2023-3545 | Cri | 0.00 | 9.8 | 0.02 | Nov 28, 2023 | Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This… | ||
| CVE-2023-3533 | Cri | 0.00 | 9.8 | 0.03 | Nov 28, 2023 | Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write. | ||
| CVE-2023-37067 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section. | ||
| CVE-2023-37066 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel. | ||
| CVE-2023-37065 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section. | ||
| CVE-2023-37064 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section. | ||
| CVE-2023-37063 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section. | ||
| CVE-2023-37062 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition. | ||
| CVE-2023-37061 | Med | 0.00 | 4.8 | 0.00 | Jul 7, 2023 | Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section. | ||
| CVE-2023-34962 | Hig | 0.00 | 8.1 | 0.01 | Jun 8, 2023 | Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes. | ||
| CVE-2023-34961 | Med | 0.00 | 6.1 | 0.00 | Jun 8, 2023 | Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field. | ||
| CVE-2023-34959 | Med | 0.00 | 5.3 | 0.01 | Jun 8, 2023 | An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools. | ||
| CVE-2023-34958 | Med | 0.00 | 4.3 | 0.00 | Jun 8, 2023 | Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID. | ||
| CVE-2021-35415 | Med | 0.00 | 4.8 | 0.01 | Dec 3, 2021 | A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields. | ||
| CVE-2021-35414 | Cri | 0.00 | 9.8 | 0.02 | Dec 3, 2021 | Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php. | ||
| CVE-2021-35413 | Hig | 0.00 | 8.8 | 0.03 | Dec 3, 2021 | A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file. | ||
| CVE-2021-37390 | Med | 0.00 | 6.1 | 0.01 | Aug 10, 2021 | A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature). | ||
| CVE-2021-37389 | Med | 0.00 | 6.1 | 0.01 | Aug 10, 2021 | Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter. | ||
| CVE-2021-32925 | Med | 0.00 | 6.5 | 0.02 | May 13, 2021 | admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities. | ||
| CVE-2021-26746 | Med | 0.00 | 6.1 | 0.01 | Feb 19, 2021 | Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI. | ||
| CVE-2019-1000017 | Med | 0.00 | 6.5 | 0.01 | Feb 4, 2019 | Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable… | ||
| CVE-2019-1000015 | Med | 0.00 | 6.1 | 0.01 | Feb 4, 2019 | Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the… | ||
| CVE-2018-20329 | Hig | 0.00 | 8.1 | 0.01 | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information. |
- risk 0.00cvss 4.8epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by improper sanitization of the Category Name field, allowing privileged users to…
- risk 0.00cvss 7.1epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can…
- risk 0.00cvss 8.8epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username"…
- risk 0.00cvss 4.9epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version…
- risk 0.00cvss 7.2epss 0.03
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30.
- risk 0.00cvss 7.2epss 0.03
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30.
- risk 0.00cvss 7.2epss 0.03
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30.
- risk 0.00cvss 7.2epss 0.03
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30.
- risk 0.00cvss 7.2epss 0.03
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30.
- risk 0.00cvss 8.3epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
- risk 0.00cvss 9.8epss 0.01
Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.
- risk 0.00cvss 7.2epss 0.01
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched in version 1.11.30.
- risk 0.00cvss 9.8epss 0.01
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30.
- risk 0.00cvss 8.8epss 0.01
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] and POST login parameters found in /main/coursecopy/copy_course_session_selected.p…
- risk 0.00cvss 7.2epss 0.01
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following scripts: /plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php,…
- risk 0.00cvss 4.8epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists due to insufficient sanitization of CSV filenames. An attacker can upload a maliciously named CSV file (e.g., .csv) that leads…
- risk 0.00cvss 5.3epss 0.00
Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28.
- risk 0.00cvss 7.5epss 0.00
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online."
- risk 0.00cvss 6.1epss 0.00
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.
- risk 0.00cvss 5.4epss 0.00
A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.
- risk 0.00cvss 7.1epss 0.01
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.
- risk 0.00cvss 8.8epss 0.02
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
- risk 0.00cvss 8.8epss 0.02
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
- risk 0.00cvss 8.8epss 0.02
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
- risk 0.00cvss 8.8epss 0.02
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
- risk 0.00cvss 7.2epss 0.04
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
- risk 0.00cvss 7.2epss 0.04
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
- risk 0.00cvss 9.8epss 0.02
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This…
- risk 0.00cvss 9.8epss 0.03
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
- risk 0.00cvss 4.8epss 0.00
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.
- risk 0.00cvss 8.1epss 0.01
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
- risk 0.00cvss 6.1epss 0.00
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
- risk 0.00cvss 5.3epss 0.01
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
- risk 0.00cvss 4.3epss 0.00
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
- risk 0.00cvss 4.8epss 0.01
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
- risk 0.00cvss 9.8epss 0.02
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
- risk 0.00cvss 8.8epss 0.03
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
- risk 0.00cvss 6.1epss 0.01
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
- risk 0.00cvss 6.1epss 0.01
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
- risk 0.00cvss 6.5epss 0.02
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
- risk 0.00cvss 6.1epss 0.01
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
- risk 0.00cvss 6.5epss 0.01
Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable…
- risk 0.00cvss 6.1epss 0.01
Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the…
- risk 0.00cvss 8.1epss 0.01
Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.
Page 3 of 4