Description
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
Remediation
References
Related Vulnerabilities
WordPress Plugin Photo Gallery-Image Gallery by Ape Cross-Site Scripting (1.6.14)
WordPress Plugin PIKLIST-Rapid development framework Cross-Site Scripting (0.9.4.25)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2020-14384)
WordPress Plugin Prismatic Multiple Cross-Site Scripting Vulnerabilities (2.7)
WordPress Plugin UserPro-Community and User Profile Cross-Site Scripting (2.33)