First published: Fri Dec 21 2018(Updated: )
Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo Lms | =1.11.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-20329 is high with a score of 8.1.
CVE-2018-20329 is an SQL injection vulnerability in Chamilo LMS version 1.11.8 that allows users to extract and/or modify database information.
The SQL injection vulnerability in Chamilo LMS version 1.11.8 can be exploited by users with access to the sessions catalogue to extract and/or modify database information.
To fix the SQL injection vulnerability in Chamilo LMS version 1.11.8, it is recommended to update to a newer version of Chamilo LMS that includes the necessary security patches.
More information about CVE-2018-20329 can be found on the Chamilo LMS GitHub page and the Chamilo LMS support website.