Description
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2022-21252 Vulnerability (CVE-2022-21252)
MySQL CVE-2022-21637 Vulnerability (CVE-2022-21637)
Microsoft SQL Server Improper Input Validation Vulnerability (CVE-1999-0999)
WordPress Plugin WP Mobile Edition Multiple Vulnerabilities (2.4)
SharePoint Origin Validation Error Vulnerability (CVE-2020-16952)