Chamilo uses the mPDF/Mpdf library to convert HTML to PDF. This can be abused by people able to edit the HTML (so with edition permissions) to trigger a Remote Code Execution vulnerability. This affects all 1.11.* versions. Reference
416e6e61/Chamilo-RCE-PoC
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|
