Description
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15729)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Unspecified Vulnerability (3.1.6)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (5.3.0)
axios Improper Input Validation Vulnerability (CVE-2019-10742)
Jenkins Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-2101)