PT-2021-3536 · Chamilo · Chamilo
Andrejspuler
·
Published
2021-05-13
·
Updated
2022-05-16
·
CVE-2021-32925
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Chamilo versions 1.11.x
Description
The issue is related to the
admin/user import.php file in Chamilo, which reads XML data without properly disabling the ability to load external entities. This can lead to an XXE (XML External Entity) attack, potentially allowing a remote attacker to disclose protected information.Recommendations
For Chamilo versions 1.11.x, consider disabling the
admin/user import.php file or restricting its access to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the admin/user import.php file for XML data import until the issue is resolved.Exploit
Fix
XXE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chamilo