Vulnerabilities > Chamilo > Chamilo LMS > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-28 CVE-2023-4221 OS Command Injection vulnerability in Chamilo LMS
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
network
low complexity
chamilo CWE-78
8.8
2023-11-28 CVE-2023-4222 OS Command Injection vulnerability in Chamilo LMS
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
network
low complexity
chamilo CWE-78
8.8
2023-11-28 CVE-2023-4223 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo LMS
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
network
low complexity
chamilo CWE-434
8.8
2023-11-28 CVE-2023-4224 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo LMS
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
network
low complexity
chamilo CWE-434
8.8
2023-11-28 CVE-2023-4225 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo LMS
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
network
low complexity
chamilo CWE-434
8.8
2023-11-28 CVE-2023-4226 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo LMS
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
network
low complexity
chamilo CWE-434
8.8
2023-06-08 CVE-2023-34962 Unspecified vulnerability in Chamilo LMS
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
network
low complexity
chamilo
8.1
2022-04-15 CVE-2022-27421 Improper Input Validation vulnerability in Chamilo LMS
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
network
low complexity
chamilo CWE-20
7.2
2022-04-15 CVE-2022-27426 Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
network
low complexity
chamilo CWE-918
8.8
2021-12-03 CVE-2021-35413 Missing Authorization vulnerability in Chamilo LMS
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
network
low complexity
chamilo CWE-862
8.8