Julio Montoya
6 exploits
Active since Feb 2021
Chamilo 1.11.14 - Cross-Site Scripting via Agenda List URI Parameter
CVSS 6.1
Chamilo 1.11.0-1.11.15 - Authenticated XML External Entity Injection in User Import
CVSS 6.5
Chamilo < 1.11.14 - Unauthenticated SQL Injection via Search Field or Filters Parameter
CVSS 9.8
Chamilo LMS 1.11.0-1.11.16 - Authenticated Remote Code Execution via .htaccess File Upload
CVSS 8.8
Chamilo LMS 1.11.0-1.11.16 - Unauthenticated SQL Injection via doc Parameter
CVSS 9.8
Chamilo LMS 1.11.0 through 1.11.16 - Stored Cross-Site Scripting
CVSS 4.8