PT-2022-18417 · Unknown · Chamilo Lms

Published

2022-04-15

·

Updated

2022-04-25

·

CVE-2022-27423

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS version 1.11.13
Description The issue is a SQL injection vulnerability. It can be exploited via the blog id parameter at the "/blog/blog.php" API endpoint.
Recommendations For Chamilo LMS version 1.11.13, avoid using the blog id parameter in the affected API endpoint until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27423

Affected Products

Chamilo Lms