vendor:
Chamillo LMS
by:
Sohel Yousef jellyfish security team
N/A
CVSS
N/A
Arbitrary File Upload
CWE
Product Name: Chamillo LMS
Affected Version From: Chamilo 1.11.8
Affected Version To: Chamilo 1.8
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2018
Chamillo LMS 1.11.8 – Arbitrary File Upload
Any registered user can upload files and rename and change the file type to php5 or php7 by ckeditor module in my files section.
Mitigation:
Unknown