Description
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
Remediation
References
Related Vulnerabilities
Moodle Improper Privilege Management Vulnerability (CVE-2020-25699)
WordPress Plugin Contentboxes Cross-Site Scripting (1.1)
WordPress Plugin Spiffy Calendar Cross-Site Scripting (3.2.0)
WordPress Plugin Synchi Arbitrary File Deletion (5.1)
Squid Improper Input Validation Vulnerability (CVE-2014-7142)