Unserialization Vulnerability in Chamilo LMS
CVE-2018-1999019
9.8CRITICAL
What is CVE-2018-1999019?
Chamilo LMS version 11.x is susceptible to an unserialization vulnerability through the 'hash' GET parameter at the API endpoint /webservices/api/v2.php. This flaw allows attackers to exploit the system via a simple GET request, potentially leading to unauthorized remote code execution without authentication. A fix has been implemented in the commit addressing this vulnerability.