Looking for the vulnerability index of Invicti's legacy products?
Chamilo Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-27427) - Vulnerability Database

Chamilo Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-27427)

Description

A zero-code remote code injection vulnerability via configuration.php in Chamilo LMS v1.11.13 allows attackers to upload arbitrary code in the form of a new plugin.

References

Related Vulnerabilities