Description
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2424 Vulnerability (CVE-2013-2424)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.6)
Apache Tomcat Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2020-13935)
WordPress Plugin Google XML Sitemaps Cross-Site Scripting (4.0.9)
Internet Information Services Improper Input Validation Vulnerability (CVE-1999-0867)