Vulnerabilities > Chamilo > Chamilo LMS > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-06-13 CVE-2023-34944 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo LMS
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
network
low complexity
chamilo CWE-434
critical
9.8