PT-2022-10768 · Unknown · Chamilo Lms

Published

2022-03-21

·

Updated

2022-03-29

·

CVE-2021-38745

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS version 1.11.14
Description The issue allows attackers to execute arbitrary code via a crafted plugin, triggered through user interaction with the attacker's profile page. This is a zero click code injection vulnerability.
Recommendations For Chamilo LMS version 1.11.14, consider disabling the plugin functionality until a patch is available to prevent exploitation of the zero click code injection vulnerability. Restrict access to the attacker's profile page to minimize the risk of triggering the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38745

Affected Products

Chamilo Lms