Angel Fernando Quiroz Campos
82 exploits
Active since Jun 2023
Chamilo < 1.11.30 - Deserialization of Untrusted Data via Import Configuration Parameters
CVSS 4.9
Chamilo LMS < 1.11.30 - Stored Cross-Site Scripting via CSV User Import
CVSS 8.8
Chamilo <1.11.30 - Privilege Escalation
CVSS 7.1
Chamilo LMS < 1.11.30 - Stored Cross-Site Scripting via Category Name Field
CVSS 4.8
Chamilo LMS < 1.11.30 - Reflected Cross-Site Scripting via keyword_inactive Parameter
CVSS 6.1
Chamilo < 1.11.30 - Reflected Cross-Site Scripting via keyword_active Parameter
CVSS 6.1
Chamilo LMS < 1.11.30 - Authenticated Stored Cross-Site Scripting in Glossary Function
CVSS 8.3
Chamilo LMS < 1.11.30 - Cross-Site Scripting via help.php Open Parameter
CVSS 6.1
Chamilo LMS < 1.11.30 - Deserialization of Untrusted Data
CVSS 9.8
Chamilo LMS <= 1.11.20 - Command Injection
CVSS 9.8
Chamilo 1.11.0-1.11.18 - Arbitrary File Upload and Remote Code Execution via SVG File
CVSS 9.8
Chamilo LMS 1.11.0-1.11.18 - Incorrect Authorization in Student Document Download
CVSS 4.3
Chamilo LMS 1.11.0-1.11.18 - Server-Side Request Forgery via Social and Links Tools
CVSS 5.3
Chamilo LMS 1.11.0-1.11.18 - Cross-Site Scripting via Feedback Comment Field
CVSS 6.1
Chamilo LMS 1.11.0-1.11.18 - Unauthenticated Incorrect Access Control in Personal Notes
CVSS 8.1
Chamilo LMS <= 1.11.20 - Path Traversal
CVSS 9.8
Chamilo < 1.11.20 - Unauthenticated Remote Code Execution via .htaccess File Upload
CVSS 9.8
Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Languages Management
CVSS 4.8
Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Course Category Definition
CVSS 4.8
Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Careers & Promotions Management
CVSS 4.8
Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Extra Fields Management
CVSS 4.8
Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Session Category Management
CVSS 4.8
Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Skills Wheel
CVSS 4.8
Chamilo 1.11.0-1.11.20 - Authenticated Stored Cross-Site Scripting in Classes/Usergroups Management
CVSS 4.8
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via PHP File Upload
CVSS 8.8