Description
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
WordPress Plugin Titan Framework Cross-Site Scripting (1.7.5)
WordPress Plugin Quiz Maker Multiple SQL Injection Vulnerabilities (6.2.0.8)
WordPress Plugin DSubscribers SQL Injection (1.2)
WordPress Plugin Newsletter Meenews 'idnews' Parameter Cross-Site Scripting (5.1.0)
WordPress Plugin Accept Donations with PayPal Cross-Site Scripting (1.3.1)