CVE-2021-38745: Code Injection
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-38745?
CVE-2021-38745 is a zero click code injection vulnerability in Chamilo LMS v1.11.14, allowing attackers to execute arbitrary code via a crafted plugin.
How does CVE-2021-38745 work?
CVE-2021-38745 is triggered when a user interacts with the attacker's profile page in Chamilo LMS v1.11.14.
What is the severity of CVE-2021-38745?
CVE-2021-38745 has a severity rating of medium (6.8) according to the Common Vulnerability Scoring System (CVSS).
What software version is affected by CVE-2021-38745?
CVE-2021-38745 affects Chamilo LMS v1.11.14.
How can CVE-2021-38745 be mitigated?
To mitigate CVE-2021-38745, it is recommended to update Chamilo LMS to a patched version or apply the necessary security fixes provided by the vendor.