Chamilo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2021-32925 - Vulnerability Database

Chamilo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2021-32925

Medium
Reference: CVE-2021-32925
Title: Chamilo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.