📦 Chamilo

by Chamilo

🔍 What is Chamilo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-3545

CRITICAL CVSS 9.8 Nov 28, 2023

This vulnerability allows unauthenticated attackers to bypass file upload security in Chamilo LMS on Windows/Apache systems by uploading a malicious .htaccess file. Attackers can achieve remote code e...

CVE-2023-3368

CRITICAL CVSS 9.8 Nov 28, 2023

CVE-2023-3368 is an unauthenticated command injection vulnerability in Chamilo LMS that allows remote attackers to execute arbitrary commands on affected systems. This vulnerability affects Chamilo LM...

CVE-2023-34960

CRITICAL CVSS 9.8 Aug 1, 2023

A critical command injection vulnerability in Chamilo's wsConvertPpt component allows remote attackers to execute arbitrary commands on the server via crafted PowerPoint filenames in SOAP API calls. T...

CVE-2021-34187

CRITICAL CVSS 9.8 Jun 28, 2021

This SQL injection vulnerability in Chamilo LMS allows attackers to execute arbitrary SQL commands via the searchField, filters, or filters2 parameters in the model.ajax.php endpoint. It affects all C...

CVE-2021-40662

HIGH CVSS 8.8 Mar 21, 2022

This CSRF vulnerability in Chamilo LMS allows attackers to trick authenticated users into executing arbitrary commands on the server by clicking a malicious link. It affects Chamilo LMS administrators...

CVE-2021-31933

HIGH CVSS 7.2 Apr 30, 2021

This vulnerability allows remote authenticated administrators in Chamilo LMS to upload malicious PHP files through directory traversal, leading to remote code execution. Attackers can execute arbitrar...