CVE-2018-1999019
23.07.2018, 15:29
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a simple GET request to the api endpoint. This vulnerability appears to have been fixed in After commit 0de84700648f098c1fbf6b807dee28ec640efe62.
Vendor | Product | Version |
---|---|---|
chamilo | chamilo_lms | 1.11.0 |
chamilo | chamilo_lms | 1.11.0:alpha2 |
chamilo | chamilo_lms | 1.11.0:beta1 |
chamilo | chamilo_lms | 1.11.0:beta2 |
chamilo | chamilo_lms | 1.11.0:beta3 |
chamilo | chamilo_lms | 1.11.0:beta4 |
chamilo | chamilo_lms | 1.11.0:beta5 |
chamilo | chamilo_lms | 1.11.0:beta6 |
chamilo | chamilo_lms | 1.11.0:beta7 |
chamilo | chamilo_lms | 1.11.0:rc1 |
chamilo | chamilo_lms | 1.11.2 |
chamilo | chamilo_lms | 1.11.4 |
chamilo | chamilo_lms | 1.11.4:alpha1 |
chamilo | chamilo_lms | 1.11.4:alpha2 |
chamilo | chamilo_lms | 1.11.4:beta1 |
chamilo | chamilo_lms | 1.11.4:rc1 |
chamilo | chamilo_lms | 1.11.6 |
chamilo | chamilo_lms | 1.11.6:alpha1 |
chamilo | chamilo_lms | 1.11.8 |
chamilo | chamilo_lms | 1.11.8:rc1 |
𝑥
= Vulnerable software versions