GHSA-28gg-m25v-q74w
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 28, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.