Vulnerability Description
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chamilo | Chamilo | 1.11.14 |
Related Weaknesses (CWE)
References
- https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-81-20PatchVendor Advisory
- https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-81-20PatchVendor Advisory
FAQ
What is CVE-2021-38745?
CVE-2021-38745 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through ...
How severe is CVE-2021-38745?
CVE-2021-38745 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38745?
Check the references section above for vendor advisories and patch information. Affected products include: Chamilo Chamilo.