Chamilo

Chamilo Lms

129 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Veröffentlicht 10.04.2026 17:44:24
  • Zuletzt bearbeitet 17.04.2026 21:28:56

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook result view page allows any authenticated teacher to delete any student's grade result across the ...

  • EPSS 0.14%
  • Veröffentlicht 10.04.2026 17:42:24
  • Zuletzt bearbeitet 17.04.2026 21:30:03

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability in the exercise question list admin panel allows an attacker to execute arbitrary JavaScript in an authenticated teacher's browser....

  • EPSS 0.23%
  • Veröffentlicht 10.04.2026 17:37:50
  • Zuletzt bearbeitet 17.04.2026 21:31:11

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request Forgery (SSRF) vulnerability in the Social Wall feature. The endpoint read_url_with_open_graph accepts a URL from the user via th...

  • EPSS 0.24%
  • Veröffentlicht 10.04.2026 17:35:10
  • Zuletzt bearbeitet 17.04.2026 21:31:36

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. Th...

  • EPSS 0.35%
  • Veröffentlicht 10.04.2026 17:32:29
  • Zuletzt bearbeitet 17.04.2026 21:23:42

Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. User input from $_REQUEST['test'] is concatenated directly into filesystem path without canon...

  • EPSS 0.17%
  • Veröffentlicht 10.04.2026 17:22:32
  • Zuletzt bearbeitet 07.10.2026 09:10:00

Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through the use of the redirect parameter to /login. This vulnerability is fixed in 2.0-beta.2.

  • EPSS 0.19%
  • Veröffentlicht 16.03.2026 19:21:15
  • Zuletzt bearbeitet 17.03.2026 18:52:21

Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in the session category listing page. The keyword parameter from $_REQUEST is echoed directly into an HTM...

  • EPSS 0.28%
  • Veröffentlicht 16.03.2026 19:19:59
  • Zuletzt bearbeitet 17.03.2026 18:52:41

Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters date_start and date_end from $_REQUEST are embedded directly into a raw SQL string without p...

  • EPSS 0.21%
  • Veröffentlicht 16.03.2026 19:18:41
  • Zuletzt bearbeitet 17.03.2026 18:53:03

Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36.

  • EPSS 0.52%
  • Veröffentlicht 16.03.2026 19:16:37
  • Zuletzt bearbeitet 17.03.2026 18:53:29

Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation on...