Description
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
Remediation
References
Related Vulnerabilities
WordPress Plugin CMS Press Cross-Site Scripting (0.2.3)
MySQL CVE-2012-3147 Vulnerability (CVE-2012-3147)
SharePoint CVE-2021-31966 Vulnerability (CVE-2021-31966)
WordPress Plugin Media from FTP Directory Traversal (9.85)
e107 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2020)