Description
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
Remediation
References
Related Vulnerabilities
GlassFish CVE-2017-3249 Vulnerability (CVE-2017-3249)
Oracle JRE CVE-2013-2422 Vulnerability (CVE-2013-2422)
WordPress Plugin WooCommerce Possible Remote Code Execution (3.5.0)
Oracle Database Server CVE-2014-4293 Vulnerability (CVE-2014-4293)
WordPress Plugin Simple Gmail Login Stack Trace Information Disclosure (1.1.3)