Description
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Remediation
References
Related Vulnerabilities
MediaWiki Other Vulnerability (CVE-2005-2215)
WordPress Plugin Booster for WooCommerce Cross-Site Scripting (5.6.1)
Artifactory Deserialization of Untrusted Data Vulnerability (CVE-2022-0573)
WordPress Plugin Customer Service Software & Support Ticket System Cross-Site Scripting (5.10.3)
phpBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5173)