CVE-2021-38745
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
21/03/2022
Last modified:
29/03/2022
Description
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:chamilo:chamilo:1.11.14:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



