First published: Fri Apr 15 2022(Updated: )
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo Lms | >=1.11.0<=1.11.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27426 is a Server-Side Request Forgery (SSRF) vulnerability in Chamilo LMS v1.11.13.
CVE-2022-27426 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
CVE-2022-27426 has a severity score of 8.8 (high).
To fix CVE-2022-27426, update Chamilo LMS to version 1.11.16 or later.
You can find more information about CVE-2022-27426 at the following link: [Chamilo LMS Security Issues](https://support.chamilo.org/projects/1/wiki/Security_issues).