Description
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2021-2135 Vulnerability (CVE-2021-2135)
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2024-25610)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1999006)
MySQL Uncontrolled Resource Consumption Vulnerability (CVE-2020-11080)