Description
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Remediation
References
Related Vulnerabilities
WordPress Plugin Acunetix WP Security Cross-Site Request Forgery (4.0.4)
WordPress Plugin Contact Form 7 Style Cross-Site Request Forgery (3.2)
MySQL CVE-2022-21637 Vulnerability (CVE-2022-21637)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2021-4104)
Squid Improper Input Validation Vulnerability (CVE-2014-3609)