Description
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Remediation
References
Related Vulnerabilities
MySQL Other Vulnerability (CVE-2004-2149)
WordPress Plugin StatPress Cross-Site Scripting (1.2.9.1)
MongoDb CVE-2025-6709 Vulnerability (CVE-2025-6709)
WordPress Plugin Store Locator Plus for WordPress Privilege Escalation (5.5.14)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2025-3638)