Chamilo

Chamilo Lms

129 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 17.09.2026 20:11:52
  • Zuletzt bearbeitet 24.09.2026 21:25:27

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, in...

  • EPSS -
  • Veröffentlicht 17.09.2026 20:09:57
  • Zuletzt bearbeitet 29.09.2026 19:07:47

Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue and public/mai...

  • EPSS 0.27%
  • Veröffentlicht 11.09.2026 17:09:37
  • Zuletzt bearbeitet 24.09.2026 20:43:32

Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authoriz...

  • EPSS 0.29%
  • Veröffentlicht 20.07.2026 17:11:01
  • Zuletzt bearbeitet 22.07.2026 20:50:36

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a ...

  • EPSS 0.24%
  • Veröffentlicht 20.07.2026 17:08:21
  • Zuletzt bearbeitet 21.08.2026 20:16:34

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full...

  • EPSS 0.32%
  • Veröffentlicht 14.04.2026 21:37:55
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenticated user with ROLE_STUDENT to escalate their priv...

Exploit
  • EPSS 1.76%
  • Veröffentlicht 14.04.2026 21:33:13
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code ...

  • EPSS 0.2%
  • Veröffentlicht 14.04.2026 21:29:06
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object Reference (IDOR), allowing an authenticated attacker to modify the user parameter in...

  • EPSS 0.23%
  • Veröffentlicht 14.04.2026 21:25:28
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to read the private course notes of...

  • EPSS 0.22%
  • Veröffentlicht 14.04.2026 21:12:48
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality, where an authenticated user can upload a malicious...