Yannick Warnier
16 exploits
Active since Dec 2018
Chamilo LMS Learning Path Progress - Insecure Direct Object Reference
CVSS 7.1
Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms
CVSS 9.4
Chamilo LMS has Weak REST API Key Generation (Predictable)
CVSS 7.5
Chamilo LMS affected by unauthenticated RCE in main/install folder
CVSS 9.8
Chamilo LMS Learning Path Progress - Insecure Direct Object Reference
CVSS 7.1
Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint
CVSS 7.1
Chamilo LMS has unauthenticated access to Twig template source files exposes application logic
CVSS 5.3
Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms
CVSS 9.4
Chamilo LMS 1.11.8 - Authenticated Cross-Site Scripting in Gradebook Dependencies Tool
CVSS 5.4
Chamilo LMS 1.11.8 - Authenticated Cross-Site Scripting in Social Groups Tool
CVSS 5.4
Chamilo LMS <1.11.8 - SQL Injection
CVSS 8.1
Chamilo Chamilo-lms <= 1.11.8 - XSS
CVSS 6.1
Chamilo Chamilo-lms <1.11.8 - Info Disclosure
CVSS 6.5
Chamilo LMS <= 1.11.24 - Command Injection
CVSS 7.2
Chamilo LMS <= 1.11.24 - Command Injection
CVSS 7.2
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via PHP File Upload
CVSS 8.8