Vulnerabilities > Chamilo > Chamilo LMS > 1.11.26

DATE CVE VULNERABILITY TITLE RISK
2022-04-15 CVE-2022-27421 Improper Input Validation vulnerability in Chamilo LMS
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
network
low complexity
chamilo CWE-20
7.2
2021-08-10 CVE-2021-37390 Cross-site Scripting vulnerability in Chamilo LMS
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
network
low complexity
chamilo CWE-79
6.1