Description
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
Remediation
References
Related Vulnerabilities
Python Improper Restriction of XML External Entity Reference Vulnerability (CVE-2013-0340)
WordPress Plugin WooCommerce OpenPOS Arbitrary File Deletion (6.4.4)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3667)
MySQL CVE-2022-21589 Vulnerability (CVE-2022-21589)
Mailman Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2021-42096)