Description
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Remediation
References
Related Vulnerabilities
TYPO3 Other Vulnerability (CVE-2012-1605)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-6532)
Jetty Improper Resource Shutdown or Release Vulnerability (CVE-2022-2191)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4303)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3412)