CVE-2022-27426
EUVD-2022-3192915.04.2022, 20:15
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| chamilo | chamilo_lms | 1.11.0 ≤ 𝑥 ≤ 1.11.16 |
𝑥
= Vulnerable software versions