Chamilo

Chamilo Lms

126 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 20.07.2026 17:11:01
  • Zuletzt bearbeitet 22.07.2026 20:50:36

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a ...

  • EPSS 0.24%
  • Veröffentlicht 20.07.2026 17:08:21
  • Zuletzt bearbeitet 22.07.2026 20:50:36

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full...

  • EPSS 0.32%
  • Veröffentlicht 14.04.2026 21:37:55
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenticated user with ROLE_STUDENT to escalate their priv...

Exploit
  • EPSS 1.76%
  • Veröffentlicht 14.04.2026 21:33:13
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code ...

  • EPSS 0.2%
  • Veröffentlicht 14.04.2026 21:29:06
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object Reference (IDOR), allowing an authenticated attacker to modify the user parameter in...

  • EPSS 0.23%
  • Veröffentlicht 14.04.2026 21:25:28
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to read the private course notes of...

  • EPSS 0.22%
  • Veröffentlicht 14.04.2026 21:12:48
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality, where an authenticated user can upload a malicious...

  • EPSS 0.34%
  • Veröffentlicht 14.04.2026 21:09:36
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at public/plugin/Pens/pens.php is accessible without authentication and accepts a user-contro...

  • EPSS 0.21%
  • Veröffentlicht 14.04.2026 21:05:35
  • Zuletzt bearbeitet 24.07.2026 23:10:00

Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because, unlike other AJAX endpoints, it does not include ...

  • EPSS 0.26%
  • Veröffentlicht 14.04.2026 21:00:19
  • Zuletzt bearbeitet 24.07.2026 23:10:00

Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint, which is an incomplete fix for CVE-2026-30881. While CVE-2026-30881 was patched by applying Securit...