Description
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
Django Use of Hard-coded Credentials Vulnerability (CVE-2016-9013)
Oracle Database Server CVE-2010-0903 Vulnerability (CVE-2010-0903)
WordPress Plugin TeraWallet-For WooCommerce Insecure Direct Object Reference (1.4.3)
WordPress Plugin Contact Bank-Contact Form Builder for WordPress Cross-Site Scripting (2.0.225)