PT-2021-3536 · Chamilo · Chamilo

Andrejspuler

·

Published

2021-05-13

·

Updated

2022-05-16

·

CVE-2021-32925

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Chamilo versions 1.11.x
Description The issue is related to the admin/user import.php file in Chamilo, which reads XML data without properly disabling the ability to load external entities. This can lead to an XXE (XML External Entity) attack, potentially allowing a remote attacker to disclose protected information.
Recommendations For Chamilo versions 1.11.x, consider disabling the admin/user import.php file or restricting its access to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the admin/user import.php file for XML data import until the issue is resolved.

Exploit

Fix

XXE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03587
CVE-2021-32925

Affected Products

Chamilo