← Back

CVE-2013-6787

nvd nist
Published: Dec 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.

Affected (10)

Products: Chamilo: Chamilo Lms
1 product
Chamilo Lms
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Chamilo
Up to 1.9.6
Version 1.8.6.2
Version 1.8.7.1
Version 1.8.7
Version 1.8.8.2
Version 1.8.8.4
Version 1.8.8.6
Version 1.9.0
Version 1.9.2
Version 1.9.4

Timeline

No history available yet.