CVE-2023-4222 – Chamilo LMS Learning Path PPT2LP Command Injection Vulnerability
https://notcve.org/view.php?id=CVE-2023-4222
28 Nov 2023 — Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. La inyección de comandos en `main/lp/openoffice_text_document.class.php` en Chamilo LMS en versiones <= 1.11.24 permite a los usuarios autorizados a cargar rutas de aprendizaje para obtener la ejecución remota de código mediante la neutralización inadecuada de caracteres especiales. • https://github.com/chamilo/chamilo-lms/commit/841a07396fed0ef27c5db13a1b700eac02754fc7 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2023-4221 – Chamilo LMS Learning Path PPT2LP Command Injection Vulnerability
https://notcve.org/view.php?id=CVE-2023-4221
28 Nov 2023 — Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. La inyección de comandos en `main/lp/openoffice_presentation.class.php` en Chamilo LMS en versiones <= 1.11.24 permite a los usuarios autorizados a cargar rutas de aprendizaje para obtener la ejecución remota de código mediante la neutralización inadecuada de caracteres especiales. • https://github.com/chamilo/chamilo-lms/commit/841a07396fed0ef27c5db13a1b700eac02754fc7 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2023-4220 – Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
https://notcve.org/view.php?id=CVE-2023-4220
28 Nov 2023 — Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell. Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en Chamilo LMS en versiones <= 1.11.24 permite a atacantes no autenticados realiza... • https://packetstorm.news/files/id/182982 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2023-3545 – Chamilo LMS Htaccess File Upload Security Bypass
https://notcve.org/view.php?id=CVE-2023-3545
28 Nov 2023 — Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution. La sanitización inadecuada en `main/inc/lib/fileUpload.lib.... • https://github.com/chamilo/chamilo-lms/commit/dc7bfce429fbd843a95a57c184b6992c4d709549 • CWE-178: Improper Handling of Case Sensitivity •
CVE-2023-3533 – Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write
https://notcve.org/view.php?id=CVE-2023-3533
28 Nov 2023 — Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write. Path Traversal en la funcionalidad de carga de archivos en `/main/webservices/additional_webservices.php` en Chamilo LMS en versiones <= 1.11.20 permite a atacantes no autenticados realizar ataques de Cross Site Scripting Almacenados y obtener ejecu... • https://github.com/chamilo/chamilo-lms/commit/37be9ce7243a30259047dd4517c48ff8b21d657a • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2023-3368 – Chamilo LMS Unauthenticated Command Injection
https://notcve.org/view.php?id=CVE-2023-3368
28 Nov 2023 — Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960. Inyección de comando en `/main/webservices/additional_webservices.php` en Chamilo LMS en versiones <= 1.11.20 permite a atacantes no autenticados obtener la ejecución remota de código mediante la neutralización inadecuada de caracteres especiales. Esta es una om... • https://github.com/chamilo/chamilo-lms/commit/37be9ce7243a30259047dd4517c48ff8b21d657a • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2023-39582
https://notcve.org/view.php?id=CVE-2023-39582
01 Sep 2023 — SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions. Una vulnerabilidad de inyección de SQL en Chamilo LMS v1.11 a v1.11.20 permite a un atacante remoto con privilegios obtener información sensible a través de las funciones de importación de sesiones. • https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-126-2023-07-18-High-impact-Low-risk-SQL-injection-by-admin-users • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-39061
https://notcve.org/view.php?id=CVE-2023-39061
21 Aug 2023 — Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code. Una vulnerabilidad de Cross-Site Request Forgery (CSRF) en Chamilo desde v1.11 a v1.11.20 permite a un atacante remoto autenticado ejecutar código arbitrario. • http://chamilo.com • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-34960 – Chamilo 1.11.18 Command Injection
https://notcve.org/view.php?id=CVE-2023-34960
01 Aug 2023 — A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name. • https://github.com/YongYe-Security/CVE-2023-34960 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-37066
https://notcve.org/view.php?id=CVE-2023-37066
07 Jul 2023 — Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel. • https://github.com/chamilo/chamilo-lms/commit/4f7b5ebf90c35999917c231276e47a4184275690 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •