Description
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30.
Remediation
References
Related Vulnerabilities
Envoy Proxy Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27492)
Jetty Improper Neutralization of Quoting Syntax Vulnerability (CVE-2023-36479)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4593)
Perl Improper Certificate Validation Vulnerability (CVE-2023-31486)