Yannick Warnier
16 exploits
Active since Dec 2018
Chamilo LMS has an Insecure Direct Object Reference (IDOR)
CVSS 7.1
Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms
CVSS 9.4
Chamilo LMS has Weak REST API Key Generation (Predictable)
CVSS 7.5
Chamilo LMS affected by unauthenticated RCE in main/install folder
CVSS 9.8
Chamilo LMS has an Insecure Direct Object Reference (IDOR)
CVSS 7.1
Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint
CVSS 7.1
Chamilo LMS has unauthenticated access to Twig template source files exposes application logic
CVSS 5.3
Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms
CVSS 9.4
Chamilo LMS <1.11.8 - XSS
CVSS 5.4
Chamilo LMS <1.11.8 - XSS
CVSS 5.4
Chamilo LMS <1.11.8 - SQL Injection
CVSS 8.1
Chamilo Chamilo-lms <= 1.11.8 - XSS
CVSS 6.1
Chamilo Chamilo-lms <1.11.8 - Info Disclosure
CVSS 6.5
Chamilo LMS <= 1.11.24 - Command Injection
CVSS 7.2
Chamilo LMS <= 1.11.24 - Command Injection
CVSS 7.2
Chamilo LMS <= 1.11.24 - RCE
CVSS 8.8