CVE-2022-27426: SSRF
Published Apr 15, 2022
·Updated
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
Affected Software
1 affected component
Chamilo Chamilo LMS>=1.11.0<=1.11.16
Remediation
Patch Available
Event History
Apr 15, 2022
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27426?
CVE-2022-27426 is a Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS v1.11.13.
2
How does CVE-2022-27426 affect Chamilo LMS?
CVE-2022-27426 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
3
What is the severity of CVE-2022-27426?
CVE-2022-27426 has a severity score of 8.8 (high).
4
How can I fix CVE-2022-27426 in Chamilo LMS?
To fix CVE-2022-27426, update Chamilo LMS to version 1.11.16 or later.
5
Where can I find more information about CVE-2022-27426?
You can find more information about CVE-2022-27426 at the following link: [Chamilo LMS Security Issues](https://support.chamilo.org/projects/1/wiki/Security_issues).