Vulnerabilities > Chamilo > Chamilo LMS

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2023-31806 Cross-site Scripting vulnerability in Chamilo LMS 1.11.18
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.
network
low complexity
chamilo CWE-79
5.4
2023-05-09 CVE-2023-31807 Cross-site Scripting vulnerability in Chamilo LMS 1.11.18
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
network
low complexity
chamilo CWE-79
5.4
2022-04-15 CVE-2022-27421 Improper Input Validation vulnerability in Chamilo LMS
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
network
low complexity
chamilo CWE-20
7.2
2022-04-15 CVE-2022-27422 Cross-site Scripting vulnerability in Chamilo LMS
A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.
network
low complexity
chamilo CWE-79
6.1
2022-04-15 CVE-2022-27423 SQL Injection vulnerability in Chamilo LMS
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.
network
low complexity
chamilo CWE-89
critical
9.8
2022-04-15 CVE-2022-27426 Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
network
low complexity
chamilo CWE-918
8.8
2021-12-03 CVE-2021-35413 Missing Authorization vulnerability in Chamilo LMS
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
network
low complexity
chamilo CWE-862
8.8
2021-12-03 CVE-2021-35414 SQL Injection vulnerability in Chamilo LMS
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
network
low complexity
chamilo CWE-89
critical
9.8
2021-12-03 CVE-2021-35415 Cross-site Scripting vulnerability in Chamilo LMS
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
network
low complexity
chamilo CWE-79
4.8
2021-11-03 CVE-2020-23126 Cross-site Scripting vulnerability in Chamilo LMS 1.11.10
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
network
low complexity
chamilo CWE-79
6.1