Vulnerabilities > Chamilo > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-15 CVE-2022-27426 Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
network
low complexity
chamilo CWE-918
8.8
2022-03-21 CVE-2021-40662 Cross-Site Request Forgery (CSRF) vulnerability in Chamilo 1.11.14
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
network
low complexity
chamilo CWE-352
8.8
2021-12-03 CVE-2021-35413 Missing Authorization vulnerability in Chamilo LMS
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
network
low complexity
chamilo CWE-862
8.8
2021-05-06 CVE-2020-23127 Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.10
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
network
low complexity
chamilo CWE-352
8.8
2021-04-30 CVE-2021-31933 Use of Incorrectly-Resolved Name or Reference vulnerability in Chamilo
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht).
network
low complexity
chamilo CWE-706
7.2
2020-01-10 CVE-2012-4030 Improper Input Validation vulnerability in Chamilo LMS
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
network
low complexity
chamilo CWE-20
7.5
2018-12-21 CVE-2018-20329 SQL Injection vulnerability in Chamilo LMS 1.11.8
Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.
network
low complexity
chamilo CWE-89
8.1