Description
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a simple GET request to the api endpoint. This vulnerability appears to have been fixed in After commit 0de84700648f098c1fbf6b807dee28ec640efe62.
Remediation
References
Related Vulnerabilities
WordPress Plugin Constant Contact Forms Cross-Site Scripting (1.8.7)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6104)
WordPress Plugin underConstruction Cross-Site Request Forgery (1.08)
WordPress Plugin WP User Frontend Arbitrary File Upload (2.3.10)
WordPress Plugin uTubeVideo Gallery Cross-Site Scripting (2.0.7)