Chamilo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2021-32925
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.