Chamilo

Chamilo Lms

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Veröffentlicht 10.08.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:15:04

A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

Exploit
  • EPSS 0.56%
  • Veröffentlicht 10.08.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:15:04

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration si...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 06.05.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:13:35

Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 06.05.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:13:35

Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.

  • EPSS 0.53%
  • Veröffentlicht 10.01.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 01:42:04

Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 04.01.2020 07:15:10
  • Zuletzt bearbeitet 21.11.2024 02:40:53

Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

Exploit
  • EPSS 3.51%
  • Veröffentlicht 30.06.2019 16:15:09
  • Zuletzt bearbeitet 21.11.2024 04:24:09

Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This...

  • EPSS 0.24%
  • Veröffentlicht 04.02.2019 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:17:40

Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a me...

  • EPSS 0.23%
  • Veröffentlicht 04.02.2019 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:17:41

Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attac...

  • EPSS 0.19%
  • Veröffentlicht 21.12.2018 06:29:00
  • Zuletzt bearbeitet 21.11.2024 04:01:14

Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This...