Description
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
Ruby on Rails Resource Management Errors Vulnerability (CVE-2015-7581)
Jenkins CVE-2014-2060 Vulnerability (CVE-2014-2060)
SharePoint CVE-2020-17017 Vulnerability (CVE-2020-17017)
Oracle Database Server CVE-2008-0339 Vulnerability (CVE-2008-0339)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-12157)