CVE-2021-32925: XEE
Published May 13, 2021
·Updated
admin/userimport.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
Affected Software
1 affected component
Chamilo Chamilo>=1.11.0<=1.11.16
Remediation
Event History
May 13, 2021
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
Description
Frequently Asked Questions
1
What is CVE-2021-32925?
CVE-2021-32925 is a vulnerability in Chamilo 1.11.x that allows the reading of XML data without disabling the ability to load external entities.
2
What is the severity level of CVE-2021-32925?
CVE-2021-32925 has a severity level of medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2021-32925?
Chamilo versions 1.11.0 to 1.11.16 are affected by CVE-2021-32925.
4
How can I fix CVE-2021-32925?
To fix CVE-2021-32925, update Chamilo to a version higher than 1.11.16 and apply the necessary patches.
5
Where can I find more information about CVE-2021-32925?
You can find more information about CVE-2021-32925 on the GitHub page and the official Chamilo support page.