main/inc/ajax/model.ajax.php in Chamilo up to and including 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
chamilo chamilo