Description
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2017-10349 Vulnerability (CVE-2017-10349)
WordPress Plugin Woosaleskit Bar Cross-Site Scripting (1.0.0)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31554)
WordPress Plugin WooCommerce Object Injection (2.3.10)
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (7.1.04)