Description
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
Remediation
References
Related Vulnerabilities
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1184)
WordPress Plugin CM Pop-Up banners for WordPress Cross-Site Scripting (1.4.10)
WordPress Plugin WPML (WordPress Multilingual) Cross-Site Scripting (3.6.3)
WebLogic Other Vulnerability (CVE-2020-10672)
Perl Improper Input Validation Vulnerability (CVE-2010-4777)