Description
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
Remediation
References
Related Vulnerabilities
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-7923)
WordPress Plugin WordPress Video Player Cross-Site Scripting (1.5.1)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-9481)
Nginx Out-of-bounds Read Vulnerability (CVE-2023-27727)
WordPress Plugin Premium Blocks for Gutenberg Unspecified Vulnerability (1.7.4)