Description
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.
Remediation
References
Related Vulnerabilities
osCommerce Other Vulnerability (CVE-2004-2021)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2015-8103)
PHP Improper Input Validation Vulnerability (CVE-2009-1272)
Atlassian Jira CVE-2020-14165 Vulnerability (CVE-2020-14165)
Django Improper Access Control Vulnerability (CVE-2016-2048)