Description
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
OpenSSL Numeric Errors Vulnerability (CVE-2012-2333)
WebLogic CVE-2023-22072 Vulnerability (CVE-2023-22072)
WeBid Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7118)
MySQL CVE-2013-0385 Vulnerability (CVE-2013-0385)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-41308)