Angel Fernando Quiroz Campos
82 exploits
Active since Jun 2023
Chamilo LMS < 1.11.30 - SQL Injection via POST resource[document] Parameter
CVSS 8.8
Chamilo < 1.11.30 - Deserialization of Untrusted Data via Import Configuration Parameters
CVSS 4.9
Chamilo LMS < 1.11.30 - Authenticated Stored Cross-Site Scripting in Glossary Function
CVSS 8.3
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
CVSS 7.1
Chamilo LMS < 1.11.30 - SQL Injection via POST resource[document] Parameter
CVSS 8.8
Chamilo <1.11.30 - Command Injection
CVSS 7.2
Chamilo < 1.11.30 - Deserialization of Untrusted Data via Import Configuration Parameters
CVSS 4.9
Chamilo LMS < 1.11.30 - Authenticated Stored Cross-Site Scripting in Glossary Function
CVSS 8.3
Chamilo LMS < 1.11.30 - Cross-Site Scripting via help.php Open Parameter
CVSS 6.1
Session Fixation in Chamilo LMS
CVSS 7.5
Server-Side Request Forgery (SSRF) in Chamilo LMS
CVSS 7.7
Chamilo LMS Gradebook Results - Insecure Direct Object Reference
CVSS 7.1
OS Command Injection in Chamilo LMS 1.11.36
CVSS 9.1
Chamilo LMS Gradebook Evaluations - Insecure Direct Object Reference
CVSS 7.1
Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE
CVSS 7.5
Chamilo LMS Session Course Edit page - Open Redirect
CVSS 4.7
Chamilo LMS XML Parsing - XML External Entity Injection
CVSS 5.3
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
CVSS 5.4
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
CVSS 7.1
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
CVSS 8.6
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
CVSS 5.4
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
CVSS 7.1
Chamilo LMS has OS Command Injection via export_all_certificates action
CVSS 8.8
OS Command Injection in Chamilo LMS 1.11.36
CVSS 9.1
Chamilo LMS Gradebook Evaluations - Insecure Direct Object Reference
CVSS 7.1