Description
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin TAuto Poster includes Backdoor [Only if downloaded via the vendor website] (1.4.5)
Apache read beyond bounds via ap_rwrite() Vulnerability (CVE-2022-28614)
Oracle Application Server Other Vulnerability (CVE-2002-1089)
WordPress Plugin Discount Rules for WooCommerce Security Bypass (2.2.0)