高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| chamilo | chamilo-lms | < 1.11.38 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
| CVE-2026-33707 | 9.4 CRITICAL | Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms |
| CVE-2026-32892 | 9.1 CRITICAL | OS Command Injection in Chamilo LMS 1.11.36 |
| CVE-2026-33618 | 8.8 HIGH | Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings |
| CVE-2026-31939 | 8.3 HIGH | Path Traversal (Arbitrary File Delete) in Chamilo LMS |
| CVE-2026-31941 | 7.7 HIGH | Server-Side Request Forgery (SSRF) in Chamilo LMS |
| CVE-2026-32931 | 7.5 HIGH | Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Le |
| CVE-2026-33710 | 7.5 HIGH | Chamilo LMS has Weak REST API Key Generation (Predictable) |
| CVE-2026-32930 | 7.1 HIGH | Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership |
| CVE-2026-32894 | 7.1 HIGH | Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade R |
| CVE-2026-33706 | 7.1 HIGH | Chamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher) |
| CVE-2026-33704 | 7.1 HIGH | Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint |
| CVE-2026-33702 | 7.1 HIGH | Chamilo LMS has an Insecure Direct Object Reference (IDOR) |
| CVE-2026-33708 | 6.5 MEDIUM | Chamilo LMS has REST API PII Exposure via get_user_info_from_username |
| CVE-2026-33141 | 6.5 MEDIUM | Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data |
| CVE-2026-33736 | 6.5 MEDIUM | Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure |
| CVE-2026-32893 | 5.4 MEDIUM | Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List |
| CVE-2026-33705 | 5.3 MEDIUM | Chamilo LMS has unauthenticated access to Twig template source files exposes application l |
| CVE-2026-33737 | 5.3 MEDIUM | Chamilo LMS has an XML External Entity (XXE) Injection |
| CVE-2026-32932 | 4.7 MEDIUM | Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit |
| CVE-2025-66447 | Chamilo LMS has validation-less redirect on login page |
Showing 20 of 23 CVEs. View all on vendor page →
まだコメントはありません