CVE-2021-38745

MEDIUM

Chamilo LMS <1.11.14 - Code Injection

Title source: llm
STIX 2.1

Description

Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.

Scores

CVSS v3 6.8
EPSS 0.0080
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
chamilo/chamilo 1.11.14
Published Mar 21, 2022
Tracked Since Feb 18, 2026