Vulnerability index

Browse CVEs

127 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chamilo Lms MEDIUM 5.4
CVE-2023-31800

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 5.4
CVE-2023-31802

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url par…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 5.4
CVE-2023-31804

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameter…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo HIGH 8.8
CVE-2022-42029

Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'…

Mitigation only
Fix from $1,950 2022-10-17
Chamilo HIGH 8.8
CVE-2022-40407

A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.

No fix yet
Fix from $1,950 2022-09-29
Chamilo Lms CRITICAL 9.8
CVE-2022-27423

Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.

Fix: after 1.11.16
Fix from $2,300 2022-04-15
Chamilo Lms HIGH 8.8
CVE-2022-27426

A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands…

Fix: after 1.11.16
Fix from $1,950 2022-04-15
Chamilo Lms HIGH 7.2
CVE-2022-27421

Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.

Fix: after 1.11.14
Fix from $1,950 2022-04-15
Chamilo Lms MEDIUM 6.1
CVE-2022-27422

A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user inter…

Fix: after 1.11.16
Fix from $1,600 2022-04-15
Chamilo MEDIUM 6.1
CVE-2022-27425

Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php.

Fix: after 1.11.16
Fix from $1,600 2022-04-15
Chamilo HIGH 8.8
CVE-2021-40662

A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a…

Patch available
Fix from $1,950 2022-03-21
Chamilo MEDIUM 6.8
CVE-2021-38745

Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a craft…

Patch available
Fix from $1,600 2022-03-21
Chamilo Lms CRITICAL 9.8
CVE-2021-35414

Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.

Fix: after 1.11.16
Fix from $2,300 2021-12-03
Chamilo Lms HIGH 8.8
CVE-2021-35413

A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary…

Fix: after 1.11.16
Fix from $1,950 2021-12-03
Chamilo MEDIUM 6.1
CVE-2021-43687

chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin…

Patch available
Fix from $1,600 2021-12-01
Chamilo Lms MEDIUM 6.1
CVE-2020-23126

Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network fri…

Patch available
Fix from $1,600 2021-11-03
Chamilo MEDIUM 6.1
CVE-2021-37389

Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

Patch available
Fix from $1,600 2021-08-10
Chamilo Lms MEDIUM 6.1
CVE-2021-37390

A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

Fix: 1.11.14+
Fix from $1,600 2021-08-10
Chamilo Lms MEDIUM 5.4
CVE-2021-37391

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.…

Fix: 1.11.14+
Fix from $1,600 2021-08-10
Chamilo CRITICAL 9.8
CVE-2021-34187EPSS 16%

main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

Fix: after 1.11.14
Fix from $2,300 2021-06-28
Chamilo MEDIUM 6.5
CVE-2021-32925

admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.

Fix: after 1.11.16
Fix from $1,600 2021-05-13
Chamilo Lms HIGH 8.8
CVE-2020-23127

Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

Patch available
Fix from $1,950 2021-05-06
Chamilo HIGH 7.2
CVE-2021-31933EPSS 14%

A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and …

Fix: after 1.11.14
Fix from $1,950 2021-04-30
Chamilo MEDIUM 6.1
CVE-2021-26746

Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.

Patch available
Fix from $1,600 2021-02-19
Chamilo MEDIUM 6.1
CVE-2012-4029

Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web scri…

Fix: 1.8.8.6+
Fix from $1,600 2020-02-08
Chamilo MEDIUM 6.1
CVE-2013-0739

Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.

Mitigation only
Fix from $1,600 2020-01-30
Chamilo MEDIUM 6.1
CVE-2013-0738

Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.

Mitigation only
Fix from $1,600 2020-01-30
Chamilo Lms HIGH 7.5
CVE-2012-4030

Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary…

Fix: 1.8.8.6+
Fix from $1,950 2020-01-10
Chamilo Lms MEDIUM 6.1
CVE-2015-9540

Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

Fix: after 1.9.10.2
Fix from $1,600 2020-01-04
Chamilo Lms CRITICAL 9.8
CVE-2019-13082

Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor…

No fix yet
Fix from $2,300 2019-06-30