Description
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Remediation
References
Related Vulnerabilities
Moodle URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-14831)
WordPress Plugin Simple File Downloader Cross-Site Scripting (1.0.4)
Lighttpd Inadequate Encryption Strength Vulnerability (CVE-2013-4508)
Joomla! Core 3.x.x Security Bypass (3.8.0 - 3.9.3)
Chart.js Improper Input Validation Vulnerability (CVE-2020-7746)