CVE-2024-47886
- EPSS 0.91%
- Veröffentlicht 02.03.2026 14:23:50
- Zuletzt bearbeitet 03.03.2026 19:11:21
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization pl...
CVE-2018-25158
- EPSS 0.38%
- Veröffentlicht 20.02.2026 22:54:44
- Zuletzt bearbeitet 15.04.2026 00:35:42
Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, r...
CVE-2026-1106
- EPSS 0.4%
- Veröffentlicht 18.01.2026 00:02:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of the component Legal Consent Handler. Performing a manipulation of the arg...
CVE-2025-69581
- EPSS 0.22%
- Veröffentlicht 16.01.2026 00:00:00
- Zuletzt bearbeitet 05.02.2026 21:46:04
An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all personal data, al...
CVE-2025-26153
- EPSS 0.33%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.
CVE-2024-51142
- EPSS 0.34%
- Veröffentlicht 15.11.2024 19:15:07
- Zuletzt bearbeitet 18.04.2025 02:29:49
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
CVE-2024-30616
- EPSS 0.6%
- Veröffentlicht 04.11.2024 19:15:06
- Zuletzt bearbeitet 18.04.2025 13:39:57
Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.
CVE-2024-30617
- EPSS 0.18%
- Veröffentlicht 04.11.2024 19:15:06
- Zuletzt bearbeitet 18.04.2025 13:55:07
A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.
CVE-2024-30618
- EPSS 0.39%
- Veröffentlicht 04.11.2024 19:15:06
- Zuletzt bearbeitet 18.04.2025 13:54:12
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.
CVE-2024-30619
- EPSS 0.38%
- Veröffentlicht 04.11.2024 19:15:06
- Zuletzt bearbeitet 18.04.2025 13:52:46
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online...