Description
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2006-3712 Vulnerability (CVE-2006-3712)
WordPress Plugin Login With Ajax Cross-Site Scripting (3.0.4)
WordPress Plugin PayPlus Payment Gateway SQL Injection (6.6.8)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9516)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (3.5.5)