CVE-2022-27426
15.04.2022, 20:15
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
Vendor | Product | Version |
---|---|---|
chamilo | chamilo_lms | 1.11.0 ≤ 𝑥 ≤ 1.11.16 |
𝑥
= Vulnerable software versions