Exploit Database

150,259 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-4225 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via Unrestricted PHP File Upload
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS 8.8
CVE-2023-4225 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via Unrestricted PHP File Upload
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS 8.8
CVE-2023-4224 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via PHP File Upload
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS 8.8
CVE-2023-4224 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via PHP File Upload
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS 8.8
CVE-2023-4223 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via PHP File Upload
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS 8.8
CVE-2023-4223 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Authenticated Remote Code Execution via PHP File Upload
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVSS 8.8
CVE-2023-4222 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Command Injection
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
CVSS 7.2
CVE-2023-4221 WRITEUP HIGH
Chamilo LMS <= 1.11.24 - Command Injection
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
CVSS 7.2
CVE-2023-4220 WRITEUP HIGH
Chamilo v1.11.24 Unrestricted File Upload PHP Webshell
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVSS 8.1
CVE-2023-34962 WRITEUP HIGH
Chamilo LMS 1.11.0-1.11.18 - Unauthenticated Incorrect Access Control in Personal Notes
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
CVSS 8.1
CVE-2023-34959 WRITEUP MEDIUM
Chamilo LMS 1.11.0-1.11.18 - Server-Side Request Forgery via Social and Links Tools
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
CVSS 5.3
CVE-2023-34959 WRITEUP MEDIUM
Chamilo LMS 1.11.0-1.11.18 - Server-Side Request Forgery via Social and Links Tools
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
CVSS 5.3
CVE-2023-34944 WRITEUP CRITICAL
Chamilo 1.11.0-1.11.18 - Arbitrary File Upload and Remote Code Execution via SVG File
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
CVSS 9.8
CVE-2023-3368 WRITEUP CRITICAL
Chamilo LMS <= 1.11.20 - Command Injection
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
CVSS 9.8
CVE-2022-40407 WRITEUP HIGH
Chamilo 1.11 - Authenticated Remote Code Execution via Zip Slip in File Upload
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
CVSS 8.8
CVE-2021-43687 WRITEUP MEDIUM
chamilo 1.11.14 - Cross-Site Scripting via jCapture Plugin Cookie
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
CVSS 6.1
CVE-2021-37391 WRITEUP MEDIUM
Chamilo LMS 1.11.0-1.11.14 - Stored Cross-Site Scripting via Social Network Invitation Feature
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
CVSS 5.4
CVE-2021-35415 WRITEUP MEDIUM
Chamilo LMS 1.11.0 through 1.11.16 - Stored Cross-Site Scripting
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
CVSS 4.8
CVE-2021-35415 WRITEUP MEDIUM
Chamilo LMS 1.11.0 through 1.11.16 - Stored Cross-Site Scripting
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
CVSS 4.8
CVE-2021-35414 WRITEUP CRITICAL
Chamilo LMS 1.11.0-1.11.16 - Unauthenticated SQL Injection via doc Parameter
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
CVSS 9.8
CVE-2021-35414 WRITEUP CRITICAL
Chamilo LMS 1.11.0-1.11.16 - Unauthenticated SQL Injection via doc Parameter
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
CVSS 9.8
CVE-2021-35413 WRITEUP HIGH
Chamilo LMS 1.11.0-1.11.16 - Authenticated Remote Code Execution via .htaccess File Upload
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
CVSS 8.8
CVE-2021-34187 WRITEUP CRITICAL
Chamilo < 1.11.14 - Unauthenticated SQL Injection via Search Field or Filters Parameter
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
CVSS 9.8
CVE-2021-31933 WRITEUP HIGH
Chamilo <= 1.11.14 - Authenticated Remote Code Execution via File Upload Parameter
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.
CVSS 7.2
CVE-2021-31933 WRITEUP HIGH
Chamilo <= 1.11.14 - Authenticated Remote Code Execution via File Upload Parameter
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.
CVSS 7.2