andrejspuler/writeups

andrejspuler/writeups

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6 MEDIUM

A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.

9.8 CRITICAL7.5 HIGH

Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.

4.8 MEDIUM3.5 LOW

A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.

6.5 MEDIUM5.5 MEDIUM

admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.