Chamilo

Chamilo Lms

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 02.03.2026 15:54:42
  • Zuletzt bearbeitet 03.03.2026 18:21:24

Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been...

  • EPSS 0.04%
  • Veröffentlicht 02.03.2026 15:54:19
  • Zuletzt bearbeitet 03.03.2026 18:21:38

Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.03.2026 15:50:45
  • Zuletzt bearbeitet 03.03.2026 18:47:26

Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.

  • EPSS 0.05%
  • Veröffentlicht 02.03.2026 15:50:20
  • Zuletzt bearbeitet 03.03.2026 18:21:58

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/add_users_to_session.php endpoint. This issue has b...

  • EPSS 0.05%
  • Veröffentlicht 02.03.2026 15:49:52
  • Zuletzt bearbeitet 03.03.2026 18:22:26

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability in the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing attackers to inje...

  • EPSS 0.05%
  • Veröffentlicht 02.03.2026 15:49:32
  • Zuletzt bearbeitet 03.03.2026 18:22:14

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/user_list.php. This issue has been patched in versi...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.03.2026 15:48:36
  • Zuletzt bearbeitet 03.03.2026 18:23:03

Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by improper sanitization of the Category Name field, allow...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.03.2026 15:48:24
  • Zuletzt bearbeitet 03.03.2026 18:23:26

Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 02.03.2026 15:47:46
  • Zuletzt bearbeitet 03.03.2026 18:23:43

Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "Fir...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.03.2026 15:46:46
  • Zuletzt bearbeitet 03.03.2026 19:42:36

Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue ha...