Description
A zero-code remote code injection vulnerability via configuration.php in Chamilo LMS v1.11.13 allows attackers to upload arbitrary code in the form of a new plugin.
Remediation
References
Related Vulnerabilities
Jenkins 7PK - Security Features Vulnerability (CVE-2014-9634)
WordPress 4.9.x Directory Traversal (4.9 - 4.9.25)
WordPress Plugin Order XML File Export Import for WooCommerce Cross-Site Request Forgery (1.3.0)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)