Description
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Remediation
References
Related Vulnerabilities
WordPress Plugin Duplicate Page Cross-Site Scripting (4.4.2)
Apache version older than 1.3.31
WordPress Plugin dsIDXpress IDX Multiple Unspecified Vulnerabilities (2.1.32)
WordPress Plugin WordPress Custom Settings Cross-Site Scripting (1.0)
WordPress Plugin WooCommerce Product Feed Manager Security Bypass (2.2.3)