Description
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
Oracle Database Server Other Vulnerability (CVE-2007-3853)
WordPress Plugin WP-Live Chat by 3CX Remote Code Execution (7.0.01)
Jenkins Improper Authentication Vulnerability (CVE-2017-2604)
Ruby Cryptographic Issues Vulnerability (CVE-2013-4363)
WordPress Plugin SlickQuiz Multiple Vulnerabilities (1.3.7.1)