Vulnerability index

Browse CVEs

127 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-31800 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter. Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31802 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url par… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31804 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameter… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 HIGH 8.8 CVE-2022-42029 Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'… Chamilo Mitigation only Fix from $1,9502022-10-17 HIGH 8.8 CVE-2022-40407 A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file. Chamilo No fix yet Fix from $1,9502022-09-29 CRITICAL 9.8 CVE-2022-27423 Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php. Chamilo Lms after 1.11.16 Fix from $2,3002022-04-15 HIGH 8.8 CVE-2022-27426 A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands… Chamilo Lms after 1.11.16 Fix from $1,9502022-04-15 HIGH 7.2 CVE-2022-27421 Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin. Chamilo Lms after 1.11.14 Fix from $1,9502022-04-15 MEDIUM 6.1 CVE-2022-27422 A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user inter… Chamilo Lms after 1.11.16 Fix from $1,6002022-04-15 MEDIUM 6.1 CVE-2022-27425 Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php. Chamilo after 1.11.16 Fix from $1,6002022-04-15 HIGH 8.8 CVE-2021-40662 A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a… Chamilo Patch available Fix from $1,9502022-03-21 MEDIUM 6.8 CVE-2021-38745 Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a craft… Chamilo Patch available Fix from $1,6002022-03-21 CRITICAL 9.8 CVE-2021-35414 Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php. Chamilo Lms after 1.11.16 Fix from $2,3002021-12-03 HIGH 8.8 CVE-2021-35413 A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary… Chamilo Lms after 1.11.16 Fix from $1,9502021-12-03 MEDIUM 6.1 CVE-2021-43687 chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin… Chamilo Patch available Fix from $1,6002021-12-01 MEDIUM 6.1 CVE-2020-23126 Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network fri… Chamilo Lms Patch available Fix from $1,6002021-11-03 MEDIUM 6.1 CVE-2021-37389 Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter. Chamilo Patch available Fix from $1,6002021-08-10 MEDIUM 6.1 CVE-2021-37390 A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature). Chamilo Lms 1.11.14+ Fix from $1,6002021-08-10 MEDIUM 5.4 CVE-2021-37391 A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.… Chamilo Lms 1.11.14+ Fix from $1,6002021-08-10 CRITICAL 9.8 CVE-2021-34187EPSS 16% main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. Chamilo after 1.11.14 Fix from $2,3002021-06-28 MEDIUM 6.5 CVE-2021-32925 admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities. Chamilo after 1.11.16 Fix from $1,6002021-05-13 HIGH 8.8 CVE-2020-23127 Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user. Chamilo Lms Patch available Fix from $1,9502021-05-06 HIGH 7.2 CVE-2021-31933EPSS 14% A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and … Chamilo after 1.11.14 Fix from $1,9502021-04-30 MEDIUM 6.1 CVE-2021-26746 Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI. Chamilo Patch available Fix from $1,6002021-02-19 MEDIUM 6.1 CVE-2012-4029 Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web scri… Chamilo 1.8.8.6+ Fix from $1,6002020-02-08 MEDIUM 6.1 CVE-2013-0739 Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script. Chamilo Mitigation only Fix from $1,6002020-01-30 MEDIUM 6.1 CVE-2013-0738 Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php. Chamilo Mitigation only Fix from $1,6002020-01-30 HIGH 7.5 CVE-2012-4030 Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary… Chamilo Lms 1.8.8.6+ Fix from $1,9502020-01-10 MEDIUM 6.1 CVE-2015-9540 Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503. Chamilo Lms after 1.9.10.2 Fix from $1,6002020-01-04 CRITICAL 9.8 CVE-2019-13082 Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor… Chamilo Lms No fix yet Fix from $2,3002019-06-30