Description
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3179)
WordPress Plugin Add Comments Cross-Site Scripting (1.0.1)
Oracle Application Server Other Vulnerability (CVE-2002-0561)
Squid Improper Input Validation Vulnerability (CVE-2021-33620)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-10545)