Vulnerabilities > Chamilo > Chamilo LMS > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-06 CVE-2020-23127 Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.10
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
network
low complexity
chamilo CWE-352
8.8
2020-01-10 CVE-2012-4030 Improper Input Validation vulnerability in Chamilo LMS
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
network
low complexity
chamilo CWE-20
7.5
2018-12-21 CVE-2018-20329 SQL Injection vulnerability in Chamilo LMS 1.11.8
Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.
network
low complexity
chamilo CWE-89
8.1