Angel Fernando Quiroz Campos
63 exploits
Active since Jun 2023
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
CVSS 8.6
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
CVSS 5.4
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
CVSS 7.1
Chamilo LMS has OS Command Injection via export_all_certificates action
CVSS 8.8
OS Command Injection in Chamilo LMS 1.11.36
CVSS 9.1
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Check
CVSS 7.1
Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE
CVSS 7.5
Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit
CVSS 4.7
Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data
CVSS 6.5
Chamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)
CVSS 7.1
Chamilo LMS has REST API PII Exposure via get_user_info_from_username
CVSS 6.5
Chamilo LMS has Weak REST API Key Generation (Predictable)
CVSS 7.5
Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure
CVSS 6.5
Chamilo LMS has an XML External Entity (XXE) Injection
CVSS 5.3
Path Traversal (Arbitrary File Delete) in Chamilo LMS
CVSS 8.3
Session Fixation in Chamilo LMS
CVSS 7.5
Server-Side Request Forgery (SSRF) in Chamilo LMS
CVSS 7.7
Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Pagination
CVSS 5.4
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade Result
CVSS 7.1
Chamilo <1.11.28 - SSRF
CVSS 5.3
Chamilo <1.11.30 - Stored XSS
CVSS 4.8
Chamilo <1.11.30 - SQL Injection
CVSS 7.2
Chamilo <1.11.30 - SQL Injection
CVSS 8.8
Chamilo <1.11.30 - SQL Injection
CVSS 9.8
Chamilo <1.11.30 - SQL Injection
CVSS 7.2