CVE-2023-3545
- EPSS 2.99%
- Veröffentlicht 28.11.2023 07:15:42
- Zuletzt bearbeitet 21.11.2024 08:17:30
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `....
CVE-2023-3533
- EPSS 3.24%
- Veröffentlicht 28.11.2023 07:15:42
- Zuletzt bearbeitet 21.11.2024 08:17:28
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary fi...
CVE-2023-3368
- EPSS 84.76%
- Veröffentlicht 28.11.2023 07:15:41
- Zuletzt bearbeitet 21.11.2024 08:17:07
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
CVE-2023-39061
- EPSS 0.53%
- Veröffentlicht 21.08.2023 17:15:48
- Zuletzt bearbeitet 21.11.2024 08:14:42
Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.
CVE-2023-34960
- EPSS 93.99%
- Veröffentlicht 01.08.2023 02:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:43
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
CVE-2023-37067
- EPSS 0.43%
- Veröffentlicht 07.07.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:02
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
CVE-2023-37066
- EPSS 0.43%
- Veröffentlicht 07.07.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:02
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
CVE-2023-37065
- EPSS 0.43%
- Veröffentlicht 07.07.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:01
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
CVE-2023-37064
- EPSS 0.43%
- Veröffentlicht 07.07.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:01
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
CVE-2023-37063
- EPSS 0.43%
- Veröffentlicht 07.07.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:01
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.