Description
A zero-code remote code injection vulnerability via configuration.php in Chamilo LMS v1.11.13 allows attackers to upload arbitrary code in the form of a new plugin.
Remediation
References
Related Vulnerabilities
WordPress Plugin N-Media Post Front-end Form Arbitrary File Upload (1.0)
Joomla Improper Privilege Management Vulnerability (CVE-2018-17855)
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1111)
Moodle Incorrect Authorization Vulnerability (CVE-2020-25701)