CVE-2024-50337: Chamilo: Potential unauthenticated blind SSRF via openid function
Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50337?
CVE-2024-50337 is considered a critical vulnerability due to its potential for unauthenticated blind SSRF impacting server security.
How do I fix CVE-2024-50337?
To fix CVE-2024-50337, upgrade to Chamilo version 1.11.28 or later to mitigate the vulnerability.
What type of vulnerability is CVE-2024-50337?
CVE-2024-50337 is identified as an unauthenticated blind Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by CVE-2024-50337?
CVE-2024-50337 affects all versions of Chamilo prior to 1.11.28.
What functionality is exploited in CVE-2024-50337?
CVE-2024-50337 exploits the OpenId function in Chamilo, allowing attackers to make unauthorized requests on the server's behalf.