A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows malicious users to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
chamilo chamilo lms |