Description
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Remediation
References
Related Vulnerabilities
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0703)
MediaWiki Improper Access Control Vulnerability (CVE-2015-8627)
WordPress Plugin Ad Inserter-Ad Manager & AdSense Ads Multiple Vulnerabilities (1.5.2)
MySQL CVE-2019-2531 Vulnerability (CVE-2019-2531)
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-13376)