Angel Fernando Quiroz Campos
82 exploits
Active since Jun 2023
Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE
CVSS 7.5
Chamilo LMS Session Course Edit page - Open Redirect
CVSS 4.7
Chamilo LMS REST API Stats - Insecure Direct Object Reference
CVSS 6.5
Chamilo LMS REST API - Student-to-Teacher Privilege Escalation
CVSS 7.1
Chamilo LMS has REST API PII Exposure via get_user_info_from_username
CVSS 6.5
Chamilo LMS has Weak REST API Key Generation (Predictable)
CVSS 7.5
Chamilo LMS API Users - Insecure Direct Object Reference
CVSS 6.5
Chamilo LMS XML Parsing - XML External Entity Injection
CVSS 5.3
Path Traversal (Arbitrary File Delete) in Chamilo LMS
CVSS 8.3
Session Fixation in Chamilo LMS
CVSS 7.5
Server-Side Request Forgery (SSRF) in Chamilo LMS
CVSS 7.7
Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Pagination
CVSS 5.4
Chamilo LMS Gradebook Results - Insecure Direct Object Reference
CVSS 7.1
Chamilo LMS < 1.11.28 - Unauthenticated Server-Side Request Forgery via OpenId Function
CVSS 5.3
Chamilo LMS < 1.11.30 - Stored Cross-Site Scripting via CSV Filename
CVSS 4.8
Chamilo LMS < 1.11.30 - SQL Injection via GET Value Parameter
CVSS 7.2
Chamilo LMS < 1.11.30 - SQL Injection via POST resource[document] Parameter
CVSS 8.8
Chamilo < 1.11.30 - SQL Injection via GET openid.assoc_handle Parameter
CVSS 9.8
Chamilo < 1.11.30 - SQL Injection via POST userFile in hotpotatoes.php
CVSS 7.2
Chamilo < 1.11.30 - Time-Based SQL Injection via Registration SOAP Endpoint
CVSS 9.8
Chamilo <1.11.30 - Command Injection
CVSS 7.2
Chamilo <1.11.30 - Command Injection
CVSS 7.2
Chamilo <1.11.30 - Command Injection
CVSS 7.2
Chamilo <1.11.30 - Command Injection
CVSS 7.2
Chamilo <1.11.30 - Command Injection
CVSS 7.2