Description
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
Remediation
References
Related Vulnerabilities
Moodle Missing Authorization Vulnerability (CVE-2019-10187)
WordPress Plugin AllWebMenus WordPress Menu 'abspath' Parameter Remote File Include (1.1.3)
WordPress Plugin PayPal Digital Goods powered by Cleeng Cross-Site Scripting (2.2.13)
WordPress Plugin Count per Day Multiple Cross-Site Scripting Vulnerabilities (3.5.4)