Description
A zero-code remote code injection vulnerability via configuration.php in Chamilo LMS v1.11.13 allows attackers to upload arbitrary code in the form of a new plugin.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21090 Vulnerability (CVE-2024-21090)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1579)
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.13)
PHP Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2014-5459)