Description
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2019-2909 Vulnerability (CVE-2019-2909)
Python Uncontrolled Resource Consumption Vulnerability (CVE-2020-14422)
Dolibarr Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-14240)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2010-2950)