Description
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21589 Vulnerability (CVE-2022-21589)
WordPress Plugin Structured Content (JSON-LD) #wpsc Cross-Site Scripting (1.5)
Perl Improper Handling of Exceptional Conditions Vulnerability (CVE-2023-47100)
WordPress Plugin MathJax-LaTeX Cross-Site Request Forgery (1.1)
Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949)